@nlembrechts Good Explaination, Thanks for that. I've faced with the same issue, and captured the incoming packets to rsyslog collector and the rsyslog daemon was not really able to write all the incoming message to the target directory. when I've changed the protocol to UDP all went fine. I'd rather like to mention about the case on CyberArk customer portal: Cyberark link
... View more