I didn't see any previous reports on the forums about this, so here's the problem:
When logging about 800 messages per second to remote host and causing a service interruption via an rsyslog restart (with 5 second pause) on the remote host, I see that some messages from 2-3 seconds into the service interruption are lost, while all of them from 4-5 seconds into the service interruption are lost. Also, when doubling the messages per second, it appears that the queueing does not work as soon as the service interruption begins. Testing with 500 messages per second works fine, and sending 500 from three hosts at a time, for a total of 1,500 messages per second works fine, so it appears to be a client limitation of sorts. There is never a problem resuming after the interruption. Any thoughts?
Dan.


