Getting Data In

UDP and the 1472 bytes limit

danielbb
Motivator

We are receiving syslog data via UDP and we noticed that some data is missing.

When running - 

tcpdump -i eth0 port <udp port>

I see lines such as - 

UDP, bad length 5158 > 1472


And the data is not being ingested. 

https://eur01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fnetworkengineering.stackexchange.c...   says - 

The 1472 is the maximum payload length for the UDP datagram.

Any ideas how to deal with it?




 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk &#43; Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...