i am working with a backlevel version of rsyslogd, so i don't have any
hint of that in there.  oh well...

the remote endpoint is, for all intents and purposes, a black hole; it can
be any number of different SIEM or log transport systems, but the main
limiter is the "default" 8k barrier.  my json records can exceed that
limit without trying very hard.  i don't think i can unilaterally compress
them either...  that would probably make them incomprehensible to a
non-zero subset of my targets!

On 10/25/17, 12:12, "David Lang" <da...@lang.hm> wrote:

>There was a recent config option to imfile to allow you to configure
>between 
>trucating the message and splitting the message to have more of it appear
>in 
>another message
>
>There is no way for rsyslog to combine messages once they have been
>split, it 
>processes messages one at a time.
>
>David Lang

_______________________________________________
rsyslog mailing list
http://lists.adiscon.net/mailman/listinfo/rsyslog
http://www.rsyslog.com/professional-services/
What's up with rsyslog? Follow https://twitter.com/rgerhards
NOTE WELL: This is a PUBLIC mailing list, posts are ARCHIVED by a myriad of 
sites beyond our control. PLEASE UNSUBSCRIBE and DO NOT POST if you DON'T LIKE 
THAT.

Reply via email to