Hi everyone,
We have the following setup:
Check Point Firewall is configured to send logs via syslog over UDP (port 514).
Logs are received by a Linux server running rsyslog.
rsyslog writes these logs to a local file (e.g., /var/log/CheckPoint.log).
Splunk (on the same server) reads this file and indexes the logs
Although the Check Point firewall sends complete logs (visible in tcpdump, including structured data and original timestamps), only a truncated version of the log is written to the file by rsyslog. Specifically:
The structured message body is missing.
Only the syslog header (timestamp, hostname, program name) appears in the file.
Can anyonehelp !!
Ty
Hi @josevg1981
It sounds like this is an rsyslog configuration issue, rather than a Splunk problem however I'll do my best to help.
Check your rsyslog configuration and verify message size limits in /etc/rsyslog.conf - what is your $MaxMessageSize? Try increasing:
$MaxMessageSize 64k
Check for any template formatting that might be stripping content, does the template output the %msg% content?
# Look for custom templates that only capture certain fields $template CheckPointFormat,"%timestamp% %hostname% %programname%: %msg%\n"
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing
Hi livehybrid :
Ty , i try to change the default template for this Template="RSYSLOG_SyslogProtocol23Format" and now it works !!!! Ty for thew help
Hi @josevg1981
It sounds like this is an rsyslog configuration issue, rather than a Splunk problem however I'll do my best to help.
Check your rsyslog configuration and verify message size limits in /etc/rsyslog.conf - what is your $MaxMessageSize? Try increasing:
$MaxMessageSize 64k
Check for any template formatting that might be stripping content, does the template output the %msg% content?
# Look for custom templates that only capture certain fields $template CheckPointFormat,"%timestamp% %hostname% %programname%: %msg%\n"
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing