<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: output syslog blocked at 1000 characters in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/output-syslog-blocked-at-1000-characters/m-p/490217#M83789</link>
    <description>&lt;P&gt;I agree with @richgalloway , but according to the syslog-ng documentation the message size is limited to 64kb for SDATA and 256mb for IETF&lt;BR /&gt;
&lt;A href="https://www.syslog-ng.com/technical-documents/doc/syslog-ng-open-source-edition/3.16/administration-guide/option-description-log-msg-size"&gt;https://www.syslog-ng.com/technical-documents/doc/syslog-ng-open-source-edition/3.16/administration-guide/option-description-log-msg-size&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 10 Mar 2020 17:32:22 GMT</pubDate>
    <dc:creator>mydog8it</dc:creator>
    <dc:date>2020-03-10T17:32:22Z</dc:date>
    <item>
      <title>output syslog blocked at 1000 characters</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/output-syslog-blocked-at-1000-characters/m-p/490215#M83787</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I want tu use syslog-ng to send windows logs from a heavy forwarder to an indexer. But I got a problem, the message is truncated to the first 1kb of data (due to the RFC). Do I have any solution to send my message through syslog without being truncated?&lt;/P&gt;

&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 16:15:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/output-syslog-blocked-at-1000-characters/m-p/490215#M83787</guid>
      <dc:creator>paulquinonero</dc:creator>
      <dc:date>2020-03-10T16:15:02Z</dc:date>
    </item>
    <item>
      <title>Re: output syslog blocked at 1000 characters</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/output-syslog-blocked-at-1000-characters/m-p/490216#M83788</link>
      <description>&lt;P&gt;If the HF is running on a Windows box then there is no need for syslog.  Forwarders support Windows logs and can send them directly to indexers without an intermediate service.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 16:40:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/output-syslog-blocked-at-1000-characters/m-p/490216#M83788</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-03-10T16:40:08Z</dc:date>
    </item>
    <item>
      <title>Re: output syslog blocked at 1000 characters</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/output-syslog-blocked-at-1000-characters/m-p/490217#M83789</link>
      <description>&lt;P&gt;I agree with @richgalloway , but according to the syslog-ng documentation the message size is limited to 64kb for SDATA and 256mb for IETF&lt;BR /&gt;
&lt;A href="https://www.syslog-ng.com/technical-documents/doc/syslog-ng-open-source-edition/3.16/administration-guide/option-description-log-msg-size"&gt;https://www.syslog-ng.com/technical-documents/doc/syslog-ng-open-source-edition/3.16/administration-guide/option-description-log-msg-size&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 17:32:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/output-syslog-blocked-at-1000-characters/m-p/490217#M83789</guid>
      <dc:creator>mydog8it</dc:creator>
      <dc:date>2020-03-10T17:32:22Z</dc:date>
    </item>
    <item>
      <title>Re: output syslog blocked at 1000 characters</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/output-syslog-blocked-at-1000-characters/m-p/490218#M83790</link>
      <description>&lt;P&gt;I know, but I need to use syslog due to constraints imposed by my compagny. But I finaly find what I need, the maxEventSize option.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2020 08:10:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/output-syslog-blocked-at-1000-characters/m-p/490218#M83790</guid>
      <dc:creator>paulquinonero</dc:creator>
      <dc:date>2020-03-11T08:10:36Z</dc:date>
    </item>
    <item>
      <title>Re: output syslog blocked at 1000 characters</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/output-syslog-blocked-at-1000-characters/m-p/490219#M83791</link>
      <description>&lt;P&gt;The limitation is due to splunk configuration, not syslog-ng, but with the maxEventSize options I fix the problem, thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2020 08:11:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/output-syslog-blocked-at-1000-characters/m-p/490219#M83791</guid>
      <dc:creator>paulquinonero</dc:creator>
      <dc:date>2020-03-11T08:11:33Z</dc:date>
    </item>
  </channel>
</rss>

