GuideInformationIT

Inspect rsyslog input rulesets when only some sources reach Azure Monitor Agent

Can a nondefault rsyslog ruleset bypass the Azure Monitor Agent forwarding path?

A controlled technology lifecycle progressing from assessment to approved production.
DSE visual intelligenceManaged IT operationsGuide · 2 min read
Executive summary

What you need to know

Can a nondefault rsyslog ruleset bypass the Azure Monitor Agent forwarding path?

Potentially affected

Linux Azure Monitor Agent syslog collection through rsyslog inputs bound to nondefault rulesets.

DSE recommendation

Trace the affected input's ruleset before changing the DCR or treating every source on the host as equally collected.

Source facts

Microsoft’s Linux Azure Monitor Agent troubleshooting guide states that rsyslog inputs bound to a nondefault ruleset do not forward their messages to AMA. It directs administrators to inspect rsyslog.conf and rsyslog.d, and to confirm that 10-azuremonitoragent.conf is present, nonempty and readable by the syslog user. The agent’s mdsd.qos file provides fifteen-minute processed-event aggregates useful for investigating ingestion drops. Microsoft Learn.

Applicability

Use this branch when selected rsyslog inputs are missing while other host telemetry is available. The guide first calls for checking agent health and the downloaded syslog DCR configuration; this does not replace those prerequisites.

DSE recommendation

Trace the affected input’s ruleset before changing the DCR or treating every source on the host as equally collected. Identify the listener and its explicit routing configuration, then compare it with the intended forwarding path. Keep configuration changes narrowly tied to the missing input and review duplicate-forwarding risk before modifying an existing custom ruleset. Avoid declaring the host fully covered merely because another facility arrives.

Verification

Generate a harmless identifiable test message through the affected input and compare the relevant local processing evidence with the destination result. Use the same time window when inspecting the QoS aggregates, while remembering they summarize events rather than identify each message. Retain the input-to-ruleset mapping and the actual sample outcome. If the message still fails, continue the documented pipeline investigation without claiming the ruleset was the confirmed cause.

Official references

Microsoft Learn: Linux AMA troubleshooting. Source reviewed September 9, 2026.

Primary reference

Review the official source

Troubleshoot the Azure Monitor agent on Linux virtual machines and scale sets - Azure Monitor | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE