Summary
set system syslog file <name> commits successfully but never writes to the user log file.
Steps to reproduce
set system syslog file test facility all level all commit
vyos@145# sudo systemctl status rsyslog
● rsyslog.service - System Logging Service
Loaded: loaded (/lib/systemd/system/rsyslog.service; enabled; preset: enabled)
Drop-In: /run/systemd/system/rsyslog.service.d
└─override.conf
Active: active (running) since Fri 2026-07-03 15:32:53 UTC; 22s ago
TriggeredBy: ● syslog.socket
Docs: man:rsyslogd(8)
man:rsyslog.conf(5)
https://www.rsyslog.com/doc/
Main PID: 10657 (rsyslogd)
Tasks: 4 (limit: 2340)
Memory: 984.0K
CPU: 8ms
CGroup: /system.slice/rsyslog.service
└─10657 /usr/sbin/rsyslogd -n -iNONE
Jul 03 15:32:53 145 systemd[1]: Starting System Logging Service...
Jul 03 15:32:53 145 rsyslogd[10657]: error during parsing file /etc/rsyslog.d/00-vyos.conf, on or before line 10: outchannel '{'test':' not found - ignoring action line [v8.2302.0 try https://www.rsyslog.com/e/2207 ]
Jul 03 15:32:53 145 systemd[1]: Started System Logging Service.
Jul 03 15:32:53 145 rsyslogd[10657]: error during parsing file /etc/rsyslog.d/00-vyos.conf, on or before line 10: errors occurred in file '/etc/rsyslog.d/00-vyos.conf' around line 10 [v8.2302.0 try https://www.rsyslog.com/e/2207 ]
Jul 03 15:32:53 145 rsyslogd[10657]: imuxsock: Acquired UNIX socket '/run/systemd/journal/syslog' (fd 3) from systemd. [v8.2302.0]
Jul 03 15:32:53 145 rsyslogd[10657]: [origin software="rsyslogd" swVersion="8.2302.0" x-pid="10657" x-info="https://www.rsyslog.com"] start
[edit]Bug 1
Template (rsyslog.conf.j2, line 37) iterates for file_name, file_options in file.items()
but references ${{ file }} (the entire Python dict) instead of ${{ file_name }}.
Generated config:
$outchannel test,/var/log/user/test,256,...
kern.info :omfile:${'test': {'facility': {'kern': {'level': 'info'}}, ...}}rsyslog error on startup:
outchannel '{'test':' not found - ignoring action line [v8.2302.0 e/2207]Result: action line ignored, /var/log/user/test never created.
Bug 2
kbytes passed as bytes (line 31). After hot-patching bug 1 alone on the VM, the file got created, received one ~600-byte burst of rsyslog restart chatter and then dropped everything. The CLI's archive size is documented as kbytes (default 256), but the template feeds the raw number into $outchannel, which takes bytes. 600 > 256, so the limit was exceeded immediately.
Bug 3
the size-limit action calls the wrong logrotate config (line 31). When over the limit, rsyslog exec'd logrotate /etc/logrotate.d/vyos-rsyslog — the messages config — instead of the vyos-rsyslog-user config that the conf script renders for exactly this purpose. Since that never shrinks the file, rsyslog logged file size limit cmd for file '/var/log/user/test' did no resolve situation and permanently abandoned the file. So even with bug 1 fixed, the feature delivers one burst and dies.