Ryan Faircloth

Results 79 comments of Ryan Faircloth

For now, this can be worked around by using an instance of the container per TLS cert pair.

Agree will look at this post 2.0

I tested multline with windows events can you confirm the problem on a non splunk source?

yes this is here. I need to get this into a doc page https://gist.github.com/rfaircloth-splunk/fe0f051fbedfefd13c5f56dfeb0a8b3b

UDP would limtit the event to about 1200 bytes its just unusable only tcp can really be used

Also I could use a pcap of an event that produces the invalid frame header

is the splunk host linux or windows?

This is incorrect and not allowed in BSD format syslog. What is the source product have you communicated the defect to the vendor?

The log format is not bsd formatted. In a unconfigured syslog-ng instance no processing other than logging the raw message occurs sc4s performs complex processing on the structured data for...