i am working with a backlevel version of rsyslogd, so i don't have any hint of that in there. oh well...
the remote endpoint is, for all intents and purposes, a black hole; it can be any number of different SIEM or log transport systems, but the main limiter is the "default" 8k barrier. my json records can exceed that limit without trying very hard. i don't think i can unilaterally compress them either... that would probably make them incomprehensible to a non-zero subset of my targets! On 10/25/17, 12:12, "David Lang" <da...@lang.hm> wrote: >There was a recent config option to imfile to allow you to configure >between >trucating the message and splitting the message to have more of it appear >in >another message > >There is no way for rsyslog to combine messages once they have been >split, it >processes messages one at a time. > >David Lang _______________________________________________ rsyslog mailing list http://lists.adiscon.net/mailman/listinfo/rsyslog http://www.rsyslog.com/professional-services/ What's up with rsyslog? Follow https://twitter.com/rgerhards NOTE WELL: This is a PUBLIC mailing list, posts are ARCHIVED by a myriad of sites beyond our control. PLEASE UNSUBSCRIBE and DO NOT POST if you DON'T LIKE THAT.