syslog-ng-users March 2012 archive
Main Archive Page > Month Archives  > syslog-ng-users archives
syslog-ng-users: [syslog-ng] Packet fragmentation issue

[syslog-ng] Packet fragmentation issue

From: José Moreno <jmorenoa_at_nospam>
Date: Fri Mar 02 2012 - 13:40:12 GMT
To: "syslog-ng@lists.balabit.hu" <syslog-ng@lists.balabit.hu>

Hi all,

I'm running syslog-ng 2.4.1, log sources send to a log server which beside keeping the original data as is in files, forwards them in real time to a SIEM, spoofing source IP.

My problem comes after some logs are too long to fit in a single frame, log server fragments those packets when sending them to SIEM and spoofing is not performed for them.

Enviado desde mi iPhone
______________________________________________________________________________
Member info: https://lists.balabit.hu/mailman/listinfo/syslog-ng
Documentation: http://www.balabit.com/support/documentation/?product=syslog-ng
FAQ: http://www.balabit.com/wiki/syslog-ng-faq