Bug 1273549 - [RFE] Improve timestamp resolution in logs
[RFE] Improve timestamp resolution in logs
Status: CLOSED ERRATA
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: 389-ds-base (Show other bugs)
7.0
Unspecified Unspecified
unspecified Severity unspecified
: rc
: ---
Assigned To: wibrown@redhat.com
Viktor Ashirov
Petr Bokoc
: FutureFeature
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2015-10-20 12:47 EDT by Noriko Hosoi
Modified: 2016-11-03 16:33 EDT (History)
6 users (show)

See Also:
Fixed In Version: 389-ds-base-1.3.5.6-1.el7
Doc Type: Enhancement
Doc Text:
Increased accuracy of log time stamps This update increases the accuracy of time stamps in Directory Server logs from one second precision to nanosecond precision by default. This enhancement allows for a more detailed analysis of events in Directory Server, and enables external log systems to correctly rebuild and interweave logs from Directory Server. Previously, log entries contained time stamps as shown in the following example: [21/Mar/2016:12:00:59 +1000] conn=1 op=0 BIND dn="cn=Directory Manager" method=128 version=3 With this update, the same log entry contains a more accurate time stamp: [21/Mar/2016:12:00:59.061886080 +1000] conn=1 op=0 BIND dn="cn=Directory Manager" method=128 version=3 To revert to the old time stamp format, set the `nsslapd-logging-hr-timestamps-enabled` attribute to `false` in `cn=config`.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2016-11-03 16:33:24 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Noriko Hosoi 2015-10-20 12:47:45 EDT
This bug is created as a clone of upstream ticket:
https://fedorahosted.org/389/ticket/47982

Increase the resolution of the timestamp from 1 second resolution:

[05/Jan/2015:10:10:07 +0000]

to hundredth or microsecond resolution

[05/Jan/2015:10:10:07.187 +0000]

Reason:

Pulling logs from dirsrv to a centralised log server currently requires using something similar to rsyslog to pull new lines from the dirsrv log and write them to the remote server.  The most common (although not the most up-to-date) method of this is using the rsyslog imfile module which polls the dirsrv log on a set interval.

Even a low load on the dirsrv server can cause multiple log lines to be written every second.  When these lines are pulled by rsyslog and sent to the remote log consolidation server, the ordering of the log lines can be completely lost.

Example:
My development pair of FreeIPA servers can write around 30 log lines with the same date timestamp.  Once these arrive at the log consolidation server, the ordering is completely lost as the resolution goes no further than 1 second.

Issues:
I realise that there are more advanced logging methods available (using inotify in rsyslog 8.something), but RHEL 6 & 7 are 2 of the biggest deployed Linux versions and they are currently pegged at rsyslog-7.4.
Comment 11 Amita Sharma 2016-06-15 03:40:27 EDT
Build :: 389-ds-base-1.3.5.6-1.el7.x86_64

Issue is fixed, Initial testing passed. Marking the bug as VERIFIED.
Comment 14 errata-xmlrpc 2016-11-03 16:33:24 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHSA-2016-2594.html

Note You need to log in before you can comment on or make changes to this bug.