Project

General

Profile

Actions

Task #6851

open

eve/syslog: stats message too long for many default configurations

Added by Jason Ish 8 months ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

With current git master and a defautl configuration file and reading an empty pcap I'm generating a stats entry of 8659 bytes. Ubuntu, Fedora and RHEL all use rsyslog and have a default maximum of 8096 byte, however this can be configured with by modifying the rsyslog configuration.

Probably nothing more than a documentation issue.


Related issues 1 (1 open0 closed)

Related to Suricata - Task #6849: brainstorm: should certain eve ouput types be removed (eg syslog)NewOISF DevActions
Actions

Also available in: Atom PDF