Syslog Rate Limiting

Feature Overview

Syslog Rate Limiting allows administrators to control the maximum number of syslog messages a device generates per second, preventing excessive logging from overwhelming system resources. This ensures stable performance and reliable log management, especially in high-activity environments. By default, a syslog rate limit of 200 messages per second is applied unless manually changed.

Syslog Rate Limiting helps prevent log flooding, ensuring that critical messages are not lost due to excessive logging. By limiting syslog output, device CPU and memory resources are protected from overload, which is especially important in high-activity or scaled deployments. This feature maintains reliable log management, supporting effective troubleshooting and system monitoring.

Requirements

This feature has no special hardware or software requirements for feature enablement or usage.

Considerations

Consider the following when configuring and using this feature:

  • Beginning with FastIron release 10.0.10h_cd1, a syslog rate limit of 200 messages per second is applied by default unless manually changed.
  • If the number of syslog messages generated exceeds the configured rate, excess messages are dropped.
  • Disabling rate limiting (setting the value to 0) may result in high CPU usage and syslog task instability, especially in scaled setups.
  • The maximum configurable rate is 300 messages per second.

Best Practices

RUCKUS suggests the following best practices regarding syslog rate limiting:

  • Monitor system performance and syslog output after adjusting the rate limit.
  • Avoid disabling rate limiting in large or busy environments to prevent resource exhaustion and loss of critical log data.

Prerequisites

This feature has no prerequisites to feature enablement or usage.