Page MenuHomeVyOS Platform

system syslog file: rsyslog config rendered incorrectly
Closed, ResolvedPublicBUG

Description

Summary

set system syslog file <name> commits successfully but never writes to the user log file.

Steps to reproduce

set system syslog file test facility all level all
commit
vyos@145# sudo systemctl status rsyslog
● rsyslog.service - System Logging Service
     Loaded: loaded (/lib/systemd/system/rsyslog.service; enabled; preset: enabled)
    Drop-In: /run/systemd/system/rsyslog.service.d
             └─override.conf
     Active: active (running) since Fri 2026-07-03 15:32:53 UTC; 22s ago
TriggeredBy: ● syslog.socket
       Docs: man:rsyslogd(8)
             man:rsyslog.conf(5)
             https://www.rsyslog.com/doc/
   Main PID: 10657 (rsyslogd)
      Tasks: 4 (limit: 2340)
     Memory: 984.0K
        CPU: 8ms
     CGroup: /system.slice/rsyslog.service
             └─10657 /usr/sbin/rsyslogd -n -iNONE

Jul 03 15:32:53 145 systemd[1]: Starting System Logging Service...
Jul 03 15:32:53 145 rsyslogd[10657]: error during parsing file /etc/rsyslog.d/00-vyos.conf, on or before line 10: outchannel '{'test':' not found - ignoring action line [v8.2302.0 try https://www.rsyslog.com/e/2207 ]
Jul 03 15:32:53 145 systemd[1]: Started System Logging Service.
Jul 03 15:32:53 145 rsyslogd[10657]: error during parsing file /etc/rsyslog.d/00-vyos.conf, on or before line 10: errors occurred in file '/etc/rsyslog.d/00-vyos.conf' around line 10 [v8.2302.0 try https://www.rsyslog.com/e/2207 ]
Jul 03 15:32:53 145 rsyslogd[10657]: imuxsock: Acquired UNIX socket '/run/systemd/journal/syslog' (fd 3) from systemd.  [v8.2302.0]
Jul 03 15:32:53 145 rsyslogd[10657]: [origin software="rsyslogd" swVersion="8.2302.0" x-pid="10657" x-info="https://www.rsyslog.com"] start
[edit]

Bug 1

Template (rsyslog.conf.j2, line 37) iterates for file_name, file_options in file.items()
but references ${{ file }} (the entire Python dict) instead of ${{ file_name }}.

Generated config:

$outchannel test,/var/log/user/test,256,...
kern.info :omfile:${'test': {'facility': {'kern': {'level': 'info'}}, ...}}

rsyslog error on startup:

outchannel '{'test':' not found - ignoring action line [v8.2302.0 e/2207]

Result: action line ignored, /var/log/user/test never created.

Bug 2
kbytes passed as bytes (line 31). After hot-patching bug 1 alone on the VM, the file got created, received one ~600-byte burst of rsyslog restart chatter and then dropped everything. The CLI's archive size is documented as kbytes (default 256), but the template feeds the raw number into $outchannel, which takes bytes. 600 > 256, so the limit was exceeded immediately.

Bug 3

the size-limit action calls the wrong logrotate config (line 31). When over the limit, rsyslog exec'd logrotate /etc/logrotate.d/vyos-rsyslog — the messages config — instead of the vyos-rsyslog-user config that the conf script renders for exactly this purpose. Since that never shrinks the file, rsyslog logged file size limit cmd for file '/var/log/user/test' did no resolve situation and permanently abandoned the file. So even with bug 1 fixed, the feature delivers one burst and dies.

Details

Version
1.4.4
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Bug (incorrect behavior)