Hi,
I want tu use syslog-ng to send windows logs from a heavy forwarder to an indexer. But I got a problem, the message is truncated to the first 1kb of data (due to the RFC). Do I have any solution to send my message through syslog without being truncated?
Thanks in advance.
I agree with @richgalloway , but according to the syslog-ng documentation the message size is limited to 64kb for SDATA and 256mb for IETF
https://www.syslog-ng.com/technical-documents/doc/syslog-ng-open-source-edition/3.16/administration-...
I agree with @richgalloway , but according to the syslog-ng documentation the message size is limited to 64kb for SDATA and 256mb for IETF
https://www.syslog-ng.com/technical-documents/doc/syslog-ng-open-source-edition/3.16/administration-...
The limitation is due to splunk configuration, not syslog-ng, but with the maxEventSize options I fix the problem, thanks!
If the HF is running on a Windows box then there is no need for syslog. Forwarders support Windows logs and can send them directly to indexers without an intermediate service.
I know, but I need to use syslog due to constraints imposed by my compagny. But I finaly find what I need, the maxEventSize option.