I used the folliwing straitforward simple documentation to deploy a remote rsyslog server https://www.tecmint.com/install-rsyslog-centralized-logging-in-centos-ubuntu/
I have the following minimalist rsyslog configuration (/etc/rsyslog.conf) on a remote serverA, The rest of the configuration is the default /etc/rsyslog.conf configuration file on CentOS release 6.10 (Final)
#### MODULES ####
$ModLoad imuxsock # provides support for local system logging (e.g. via logger command)
$ModLoad imklog # provides kernel logging support (previously done by rklogd)
#$ModLoad immark # provides --MARK-- message capability
# Provides UDP syslog reception
$ModLoad imudp
$UDPServerRun 514
# Provides TCP syslog reception
$ModLoad imtcp
$InputTCPServerRun 514
### Rules for processing the Remote Logs
$template RemoteLogs,"/data/rsyslog/%HOSTNAME%/%PROGRAMNAME%.log"
*.* ?RemoteLogs
& ~
It allows incoming messages on port 514 (either by UPD or TCP) to be written into a file named after the programname issuing these data and into a directory named after the hostname sending the data
My issue is that when I send data (programname = dump.program) from a client host called clientB to my remote syslog serverA, the directorory /data/rsyslog/clientB is not created neither the file /data/rsyslog/clientB/dump.program.log
A tcpdump on serverA clearly shows that data a coming from clientB
$ sudo tcpdump -A dst serverA | grep clientB
<134>Oct 25 10:09:28 clientB cassandra-access: {"I-logdate":"2021-10-22 14:24:11,715","I-level":"INFO","I-process":"SocketServer","I-brokerid":"1020787186","message":"Failed authentication with 10.227.214.2/10.227.214.2 (SSL handshake failed) (org.apache.kafka.common.network.Selector)","I-MessageID":"fykfvghjw6qn2fh1","I-@Ip":"10.207.87.186","I-NomPF":"KAFKA","I-NomVM":"hwi31dev02kfkzbomomtmo02","I-PathTrace":"/hawai/logs/kafka/server.log","I-RoleVM":"MOM","I-TypePF":"DEV","I-TypeTrace":"KAFKA","I-TypeVM":"MO","I-VersionOS":"CentOS release 6.10 (Final)","I-VersionSocle":"601-029","fi
10:09:28.463674 IP clientB.42330 > hwi31dev01danazboapplitbo02.shell: Flags [.], seq 711445:712893, ack 1, win 115, options [nop,nop,TS val 3499524066 ecr 3499512980], length 1448
<134>Oct 25 10:09:28 clientB cassandra-access: {"I-logdate":"2021-10-22 14:24:12,909","I-level":"INFO","I-process":"SocketServer","I-brokerid":"1020787186","message":"Failed authentication with 10.227.214.2/10.227.214.2 (SSL handshake failed) (org.apache.kafka.common.network.Selector)","I-MessageID":"fykfvghjw6qn2fh2","I-@Ip":"10.207.87.186","I-NomPF":"KAFKA","I-NomVM":"hwi31dev02kfkzbomomtmo02","I-PathTrace":"/hawai/logs/kafka/server.log","I-RoleVM":"MOM","I-TypePF":"DEV","I-TypeTrace":"KAFKA","I-TypeVM":"MO","I-VersionOS":"CentOS release 6.10 (Final)","I-VersionSocle":"601-029","file":"/hawai/logs/kafka/server.log","pfname":"KAFKA"}
<134>Oct 25 10:09:28 clientB cassandra-access: {"I-logdate":"2021-10-22 14:24:13,655","I-level":"INFO","I-process":"SocketServer","I-brokerid":"1020787186","message":"Failed authentication with 10.227.214.2/10.227.214.2 (SSL handshake failed) (org.apache.kafka.common.network.Selector)","I-MessageID":"fykfvghjw6qn2fh3","I-@Ip":"10.207.87.186","I-NomPF":"KAFKA","I-NomVM":"hwi31dev02kfkzbomomtmo02","I-PathTrace":"/hawai/logs/kafka/server.log","I-RoleVM":"MOM","I-TypePF":"DEV","I-TypeTrace":"KAFKA","I-TypeVM":"MO","I-VersionOS":"CentOS release 6.10 (Final)","I-VersionSocle":"601-029","file":"/hawai/logs/kafka/server.log","pfname":"KAFKA"}
<134>Oct 25 10:09:28 clientB cassandra-access: {"
10:09:28.463684 IP clientB > hwi31dev01danazboapplitbo02.shell: Flags [P.], seq 712893:714150, ack 1, win 115, options [nop,nop,TS val 3499524067 ecr 3499512981], length 1257
<134>Oct 25 10:09:28 clientB cassandra-access: {"I-logdate":"2021-10-22 14:24:15,077","I-level":"INFO","I-process":"SocketServer","I-brokerid":"1020787186","message":"Failed authentication with 10.227.214.2/10.227.214.2 (SSL handshake failed) (org.apache.kafka.common.network.Selector)","I-MessageID":"fykfvghjw6qn2fh5","I-@Ip":"10.207.87.186","I-NomPF":"KAFKA","I-NomVM":"hwi31dev02kfkzbomomtmo02","I-PathTrace":"/hawai/logs/kafka/server.log","I-RoleVM":"MOM","I-TypePF":"DEV","I-TypeTrace":"KAFKA","I-TypeVM":"MO","I-VersionOS":"CentOS release 6.10 (Final)","I-VersionSocle":"601-029","file":"/hawai/logs/kafka/server.log","pfname":"KAFKA"}
My understanding therefore is that data are successfuly handle by the rsyslog service on serverA, so why are'nt they written down on /data/rsyslog/clientB/dump.program.log ?
rsyslogd -version
rsyslogd 5.8.10, compiled with:
FEATURE_REGEXP: Yes
FEATURE_LARGEFILE: No
GSSAPI Kerberos 5 support: Yes
FEATURE_DEBUG (debug build, slow code): No
32bit Atomic operations supported: Yes
64bit Atomic operations supported: Yes
Runtime Instrumentation (slow code): No
Am I missing something on the server ?
Is it a writting permissions issue ?
I am lost, any help are welcome