You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
<syslog_output> in local configuration ossec.conf does not allow to set output protocol to TCP. Wazuh is sending logs using UDP, which makes this feature useless.
Maximum size of UDP syslog message is limited by size of UDP packet (512 bytes). Alarms that are bigger (especially in json format) are then cutted, which creates corrupted JSON logs.
Tasks
The steps that have to be completed in order to close the issue.
implement TCP protocol in syslog_output
add configuration parameter "protocol" to syslog_output in ossec.conf file
Additional information
The text was updated successfully, but these errors were encountered:
I need to forward all messages, so json format would be nice. it has nothing to do with syslog in my case.
Just need to forward to SIEM. So UDP over Syslog ... is maybe not right thing ... but havent found other ways
Description
<syslog_output> in local configuration ossec.conf does not allow to set output protocol to TCP. Wazuh is sending logs using UDP, which makes this feature useless.
Maximum size of UDP syslog message is limited by size of UDP packet (512 bytes). Alarms that are bigger (especially in json format) are then cutted, which creates corrupted JSON logs.
Tasks
The steps that have to be completed in order to close the issue.
Additional information
The text was updated successfully, but these errors were encountered: