Syslog messages are split over multiple lines
search cancel

Syslog messages are split over multiple lines

book

Article ID: 310289

calendar_today

Updated On:

Products

VMware vSphere ESXi

Issue/Introduction

Symptoms:
  • Monitoring syslog messages is difficult as they are split over multiple lines
  • Syslog messages split across multiple lines
  • A new line timestamp is inserted in between setences, words, and UUIDs. For example:

    Nov 23 15:08:11 Vpxa: [2010-11-23 15:08:11.574 17AA0B90 info 'App' opID=myhost-123@4486-a5 ] [VpxLRO] -- FINISH session[521d9652-3baa-abcd-12ef-34447a6df4b2]52302e87-392c-ff27-5329-605bdd12750f -- -- vpxapi.VpxaService.retrieveChanges -- 521d9652-3b
    Nov 23 15:08:11 aa-abcd-12ef-34447a6df4b2

    In this case, the session ID 521d9652-3baa-abcd-12ef-34447a6df4b2 is split by the timestamp


Environment

VMware ESXi 4.0.x Embedded
VMware ESXi 4.1.x Installable
VMware ESXi 4.0.x Installable
VMware ESXi 4.1.x Embedded

Cause

This issue occurs because the MAX_READ attribute of the syslog source in ESX/ESXi 4.x is set to 256 bytes.

Resolution

This issue is resolved in ESX/ESXi 4.0 Update 3 and ESX/ESXi 4.1 Update 2, where the MAX_READ attribute is increased to 1024 bytes.