A modicum of research reveals that even the rsyslog documentation starts out with UDP for remote delivery: https://docs.rsyslog.com/doc/getting_started/beginner_tutori...
A modicum of research reveals that even the rsyslog documentation starts out with UDP for remote delivery: https://docs.rsyslog.com/doc/getting_started/beginner_tutori...
That documentation link probably isn't as telling as is suggested, because the next example is for tcp. In the old days before tcp support was widespread (looking at you, Java) it was common to listen for udp on localhost so it was probably a common configuration.
There's not much to debate here. Syslog is used everywhere and the main reasoosn are that it is very reliable, trivial to load balance, and popular implementations have integrity checking that is permissible in regulatory environments. You can criticize it for many things, for example that most parsers are much too liberal or that the facility and severity fields are clearly dated, but not for being unreliable.
Well, maybe go observe how a broad array of sites implement it in practice, then you might take it more seriously. Maybe you don't implement it that way, but a lot of people will just follow the tutorials or shortcut their way to something that works (but is brittle).
At any rate, I was responding directly to the claim that "No one has suggested running syslog over unreliable transport" which is obviously untrue.