Page MenuHomeVyOS Platform

Missing firewall logs
Closed, ResolvedPublicBUG

Description

Forum references:

https://forum.vyos.io/t/missing-firewal-logs/9053
https://forum.vyos.io/t/still-missing-loosing-firewall-log-capability/9081

As suggested in the topic I should create a task; I believe all relevant information in in the above references

Details

Difficulty level
Unknown (require assessment)
Version
VyOS 1.4-rolling-202206270217
Why the issue appeared?
Will be filled on close
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Bug (incorrect behavior)

Event Timeline

If the counters are visible and incrementing when checking with nft list table ip filter then I don't think this is an implementation issue. Wondering if its a problem with the syslog daemon.

sarthurdev changed the task status from Open to Confirmed.Jul 6 2022, 2:50 PM

Confirmed issue, seems to be a problem in rsyslog/logrotate. Possibly related to T4250

/var/log/message fills up to the maximum defined in /etc/rsyslog.d/vyos-rsyslog and raises an error:
rsyslogd[7678]: file size limit cmd for file '/var/log/messages' did no resolve situation

n.fort claimed this task.