OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 20.7 Legacy Series »
  • Syslog_ng causing ridiculous boot times
« previous next »
  • Print
Pages: [1]

Author Topic: Syslog_ng causing ridiculous boot times  (Read 2621 times)

loganx1121

  • Full Member
  • ***
  • Posts: 123
  • Karma: 0
    • View Profile
Syslog_ng causing ridiculous boot times
« on: January 10, 2021, 02:35:34 am »
So I've been having this issue for a while now, and I've just been dealing with it.  I googled it, found a few things, but can't seem to find an actual fix.

Every time I reboot the firewall, it hangs on "Stopping syslog_ng" and I can see on the monitor it's waiting to kill some PID.  It takes forever though, causing like 10 minute reboot times on the firewall.  I didn't have this issue in version 19 that I can remember, and it seems to be a known thing from what I'm reading?  Just wondering if anyone knows an actual fix for this. 

Thanks
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17751
  • Karma: 1620
    • View Profile
Re: Syslog_ng causing ridiculous boot times
« Reply #1 on: January 11, 2021, 07:56:26 pm »
Can I ask which version and does the health audit say anything in particular?


Cheers,
Franco
Logged

loganx1121

  • Full Member
  • ***
  • Posts: 123
  • Karma: 0
    • View Profile
Re: Syslog_ng causing ridiculous boot times
« Reply #2 on: January 14, 2021, 01:19:35 pm »
Quote from: franco on January 11, 2021, 07:56:26 pm
Can I ask which version and does the health audit say anything in particular?


Cheers,
Franco

Hey Franco.  I'm currently on 20.7.7_1 but the issue has been persistent for several versions now.  Been happening for about 6 months if not more.  The health audit shows everything is fine.
Logged

loganx1121

  • Full Member
  • ***
  • Posts: 123
  • Karma: 0
    • View Profile
Re: Syslog_ng causing ridiculous boot times
« Reply #3 on: January 14, 2021, 01:24:19 pm »
For what it's worth, I also tried installing syslog_ng from the packages section in the GUI but that didn't seem to help.  Here's the health audit:

Code: [Select]
***GOT REQUEST TO AUDIT HEALTH***
>>> Check installed kernel version
Version 20.7.6 is correct.
>>> Check for missing or altered kernel files
No problems detected.
>>> Check installed base version
Version 20.7.6 is correct.
>>> Check for missing or altered base files
No problems detected.
>>> Check for and install missing package dependencies
Checking all packages: .......... done
>>> Check for missing or altered package files
Checking all packages: .
elasticsearch5-5.6.8_5: checksum mismatch for /usr/local/etc/elasticsearch/elasticsearch.yml
Checking all packages............ done
>>> Check for core packages consistency
Checking core packages: .................................................................... done
***DONE***
« Last Edit: January 14, 2021, 01:28:34 pm by loganx1121 »
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17751
  • Karma: 1620
    • View Profile
Re: Syslog_ng causing ridiculous boot times
« Reply #4 on: January 14, 2021, 05:02:33 pm »
Seeing elasticsearch... is it possible this has something to do with sensei or some remote syslog target?

Syslog-ng errors were fixed early in 20.7.x.


Cheers,
Franco
Logged

loganx1121

  • Full Member
  • ***
  • Posts: 123
  • Karma: 0
    • View Profile
Re: Syslog_ng causing ridiculous boot times
« Reply #5 on: January 16, 2021, 02:59:40 am »
I am sending logs to a system that is using elasticsearch and then forwarding them from there to a cloud SIEM.  Yes I also have sensei running but that's been updated several times since the issue started.  What would you suggest?  Do you think this is a sensei issue?
« Last Edit: January 20, 2021, 05:15:05 am by loganx1121 »
Logged

loganx1121

  • Full Member
  • ***
  • Posts: 123
  • Karma: 0
    • View Profile
Re: Syslog_ng causing ridiculous boot times
« Reply #6 on: January 27, 2021, 02:46:58 am »
Any suggestions here?
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 20.7 Legacy Series »
  • Syslog_ng causing ridiculous boot times
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2