Hello Benedict,

You can use only the RFC5424 format without the framing from RFC6587. For that, you should use the network() driver instead of syslog() driver:
e.g.

network("`IP-ADDRESS`" port(`PORT`) transport(tcp) flags("syslog-protocol"));

Best Regards,
Gabor

From: syslog-ng <syslog-ng-bounces@lists.balabit.hu> on behalf of Hartmann Benedict - Maschinenfabrik Reinhausen <B.Hartmann@reinhausen.com>
Sent: Wednesday, May 12, 2021 12:54
To: syslog-ng@lists.balabit.hu <syslog-ng@lists.balabit.hu>
Subject: [syslog-ng] Changing message transfer for rfc6587
 
CAUTION: This email originated from outside of the organization. Do not follow guidance, click links, or open attachments unless you recognize the sender and know the content is safe.

Hello,

 

at the moment I am sending messages via

 

destination d_syslog_visu_conf_IETF

{

    syslog("`IPADRESS`" transport(TCP) port(`PORT`) `TLS_CERT`) ;

};

 

This approach will lead to the rfc6587 standard. The messages are collected via visual syslog.
Is it possible to change the message transfer mode from “octet counting” (leading message length) to “non-transparent-framing” (no leading message length) via config?

 

Best regards

Benedict Hartmann

 

MSENSE

The Reinhausen-Magazine Visit us: / Besuchen Sie uns:
ONLOAD Facebook Instagram Twitter LinkedIn

Maschinenfabrik Reinhausen GmbH
General Manager / Geschäftsführer: Dr. Nicolas Maier-Scheubeck, Wilfried Breuer, Holger Michalka
Chairman of the Board / Vors. des Aufsichtsrats: Hans-Jürgen Thaus
Registered Office / Sitz der Gesellschaft: Regensburg
Local Court Regensburg / Amtsgericht Regensburg HRB 3687

This e-mail and any attachments contain confidential and/or privileged information.
If you are not the intended recipient (or have received this e-mail in error) please notify the sender and delete this message. Thank you.
Any unauthorized copying, disclosure or distribution of the material in this e-mail is strictly forbidden.
This e-mail was scanned for viruses, vandals and malicious content.