What you need to know
Can a nondefault rsyslog ruleset bypass the Azure Monitor Agent forwarding path?
Potentially affected
Linux Azure Monitor Agent syslog collection through rsyslog inputs bound to nondefault rulesets.
DSE recommendation
Trace the affected input's ruleset before changing the DCR or treating every source on the host as equally collected.
Source facts
Microsoft’s Linux Azure Monitor Agent troubleshooting guide states that rsyslog inputs bound to a nondefault ruleset do not forward their messages to AMA. It directs administrators to inspect rsyslog.conf and rsyslog.d, and to confirm that 10-azuremonitoragent.conf is present, nonempty and readable by the syslog user. The agent’s mdsd.qos file provides fifteen-minute processed-event aggregates useful for investigating ingestion drops. Microsoft Learn.
Applicability
Use this branch when selected rsyslog inputs are missing while other host telemetry is available. The guide first calls for checking agent health and the downloaded syslog DCR configuration; this does not replace those prerequisites.
DSE recommendation
Trace the affected input’s ruleset before changing the DCR or treating every source on the host as equally collected. Identify the listener and its explicit routing configuration, then compare it with the intended forwarding path. Keep configuration changes narrowly tied to the missing input and review duplicate-forwarding risk before modifying an existing custom ruleset. Avoid declaring the host fully covered merely because another facility arrives.
Verification
Generate a harmless identifiable test message through the affected input and compare the relevant local processing evidence with the destination result. Use the same time window when inspecting the QoS aggregates, while remembering they summarize events rather than identify each message. Retain the input-to-ruleset mapping and the actual sample outcome. If the message still fails, continue the documented pipeline investigation without claiming the ruleset was the confirmed cause.
Official references
Microsoft Learn: Linux AMA troubleshooting. Source reviewed September 9, 2026.
Review the official source
Troubleshoot the Azure Monitor agent on Linux virtual machines and scale sets - Azure Monitor | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE