cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
273
Views
10
Helpful
1
Replies

Getting "nbslogpd[7188]" on CUPC RTMT

chouna789
Level 1
Level 1

Hello All,

 

I am getting bellow error log for IM&P server on RTMT. Please help in understanding the same.

"At Fri Aug 14 01:41:50 EDT 2015 on node 128.94.63.60, the following SyslogSeverityMatchFound events generated: 
SeverityMatch : Alert
MatchedEvent : Aug 14 01:41:18 palucs4upp syslog 1 nbslogpd[7188]: 85 messages were dropped  
AppID : Cisco Syslog Agent
ClusterID : 
NodeID : palucs4upp
 TimeStamp : Fri Aug 14 01:41:19 EDT 2015 

"

This is bit frequent. only count for number of drops is changing. otherwise same error code. 

 

Thanks,

Narendra

 

1 Reply 1

Manish Gogna
Cisco Employee
Cisco Employee

Hi Narendra,

Nbslogpd is the non-blocking syslog daemon, meaning that it will not block writes to the file.

Instead, the daemon will write a summary of the lines that it did not log and give access back to the file so that other file descriptors can write to the file.

Here is a link that describes this Linux daemon:


http://www.linux-ha.org/doc/users-guide/_non_blocking_logging_daemon.html

Also, here is a link that describes the concepts of blocking and non-blocking i/o:

http://www.linux-mag.com/id/308/

With that being said, there are messages that are being rate-limited from being written to the Syslog file.  (Syslog is busy)


You can start by checking the application and system logs in RTMT just before the alert is seen, they could possibly give some more information.

 

Manish

- Do rate helpful posts -