Information: Forum is in read-only mode
For details and other support options see https://www.adiscon.com/news/support-forum-set-to-read-only-mode/

Data missing from error events

Support, Questions and Discussions on MonitorWare Agent

Moderator: alorbach

Google Ads


Data missing from error events

Postby jcoder » Thu Feb 22, 2007 9:29 pm

hi,
I have been forwarding events from a log file in a windows based server to a syslog server,the additional data associated with the error event goes thru only partially i.e only a few lines go thru and the rest are lost.Is there a special configuration to get all the lines in the file thru to the syslog server?

I thought this was characteristic in case of UDP, but in this case this is happening over the TCP :?

Hope u could provide me with an insight.

Regards
Jcoder
jcoder
Avarage
 
Posts: 10
Joined: Tue Feb 20, 2007 3:11 pm

Postby alorbach » Fri Feb 23, 2007 12:20 am

Hi,

it also depends on what kind of sender you are using.
Syslog for itself is not build for larger messages, and not every receiver will be able to receive long Syslog messages.

If you could give us some more details about the syslog recipient, this would be helpfull.

best regards,
Andre Lorbach
alorbach
Site Admin
 
Posts: 1627
Joined: Thu Feb 13, 2003 11:55 am

Postby jcoder » Fri Feb 23, 2007 5:31 pm

hi,
I m sending the data from the logs to a splunk server, the lines following an error event (describing location of the error etc) do not make it completly :(
jcoder
Avarage
 
Posts: 10
Joined: Tue Feb 20, 2007 3:11 pm

Postby alorbach » Mon Feb 26, 2007 10:25 am

Then I guess that the Splunk Server treats line feeds as end of message, or can not handle larger Syslog messages.
alorbach
Site Admin
 
Posts: 1627
Joined: Thu Feb 13, 2003 11:55 am

Google Ads



Return to MonitorWare Agent

Who is online

Users browsing this forum: No registered users and 0 guests

cron