working in a container env, the ask is to have a single rsyslog process
"concentrate" logs from disparate processes and spit them out to STDOUT.
what's the *right way* to do this?
___
rsyslog mailing list
https://lists.adiscon.net/mailman/listinfo/rsys
i am working with a backlevel version of rsyslogd, so i don't have any
hint of that in there. oh well...
the remote endpoint is, for all intents and purposes, a black hole; it can
be any number of different SIEM or log transport systems, but the main
limiter is the "default" 8k barrier. my json
;there is no generic answer to the question of how do I put 10k of data
>into a 1k
>message without loosing anything :-)
>
>David Lang
>
> On Wed, 25 Oct 2017, Randall Diffenderfer via rsyslog wrote:
>
>> Date: Wed, 25 Oct 2017 18:48:52 +
>> From: Randall D
r 25, 2017 at 11:33
To: rsyslog-users mailto:rsyslog@lists.adiscon.com>>
Cc: Randall Diffenderfer
mailto:rdiffender...@proofpoint.com>>
Subject: Re: [rsyslog] handling oversized messages
It may sound dumb, but: increase n! That's why this setting exists.
Rainer
Sent from phone,
ound dumb, but: increase n! That's why this setting exists.
Rainer
Sent from phone, thus brief.
Am 25.10.2017 19:48 schrieb "Randall Diffenderfer via rsyslog"
mailto:rsyslog@lists.adiscon.com>>:
given the global setting of "maxmessagesize=N", what is my recours
given the global setting of "maxmessagesize=N", what is my recourse if i
need to process a message > N in imfile?
in other i/o modules? it appears the message is truncated at ~N, and not
split (which is what i thought i had seen in the past...)
___
r
6 matches
Mail list logo