Long messages being truncated when sent using syslog_output.
-
- Forum User
- Posts: 6
- Joined: Fri Feb 15, 2019 3:31 am
- Location: Beirut
Long messages being truncated when sent using syslog_output.
Hey all. We have some rather long messages, around 3000 characters in size. Unfortunately they are being truncated. As you can see in the image below, the end of the field is cut off.
Is it possible to increase the message limit so that they would no longer be truncated? Perhaps using something other than syslog_output?
We’re using the following Ossec 3.1 for log collection, sending messages to a CEF UDP input in Graylog 2.5.
Is it possible to increase the message limit so that they would no longer be truncated? Perhaps using something other than syslog_output?
We’re using the following Ossec 3.1 for log collection, sending messages to a CEF UDP input in Graylog 2.5.
- mikeshinn
- Atomicorp Staff - Site Admin
- Posts: 4149
- Joined: Thu Feb 07, 2008 7:49 pm
- Location: Chantilly, VA
Re: Long messages being truncated when sent using syslog_out
I know in the past this limit was required because not all syslog listeners could handle messages larger than that.
Michael Shinn
Atomicorp - Security For Everyone
Atomicorp - Security For Everyone
-
- Forum User
- Posts: 6
- Joined: Fri Feb 15, 2019 3:31 am
- Location: Beirut
Re: Long messages being truncated when sent using syslog_out
Is there a way to work around this? We have long messages being sent and we need them to be sent in full.mikeshinn wrote:I know in the past this limit was required because not all syslog listeners could handle messages larger than that.
- mikeshinn
- Atomicorp Staff - Site Admin
- Posts: 4149
- Joined: Thu Feb 07, 2008 7:49 pm
- Location: Chantilly, VA
Re: Long messages being truncated when sent using syslog_out
Yes the latest version of AEO allows for setting effectively an unlimited limit, just make sure youre using the latest version of AEO.
Michael Shinn
Atomicorp - Security For Everyone
Atomicorp - Security For Everyone
-
- Forum User
- Posts: 6
- Joined: Fri Feb 15, 2019 3:31 am
- Location: Beirut
Re: Long messages being truncated when sent using syslog_out
I am. Where do I change this setting?mikeshinn wrote:Yes the latest version of AEO allows for setting effectively an unlimited limit, just make sure youre using the latest version of AEO.
- mikeshinn
- Atomicorp Staff - Site Admin
- Posts: 4149
- Joined: Thu Feb 07, 2008 7:49 pm
- Location: Chantilly, VA
Re: Long messages being truncated when sent using syslog_out
Sorry if I wasnt clear, the latest version of AEO has no limit. What version of AEO is the hub using?
Just run this command:
asl -v
Just run this command:
asl -v
Michael Shinn
Atomicorp - Security For Everyone
Atomicorp - Security For Everyone
-
- Forum User
- Posts: 6
- Joined: Fri Feb 15, 2019 3:31 am
- Location: Beirut
Re: Long messages being truncated when sent using syslog_out
yum list installed | grep ossec
ossec-hids.x86_64 1:3.3.0-7006.el7.art @atomic
ossec-hids-server.x86_64 1:3.3.0-7006.el7.art @atomic
ossec-hids.x86_64 1:3.3.0-7006.el7.art @atomic
ossec-hids-server.x86_64 1:3.3.0-7006.el7.art @atomic
- mikeshinn
- Atomicorp Staff - Site Admin
- Posts: 4149
- Joined: Thu Feb 07, 2008 7:49 pm
- Location: Chantilly, VA
Re: Long messages being truncated when sent using syslog_out
Thats pretty old, I dont think we've put out a version of AEO using a version of OSSEC that old. Can you send me the version number for AEO with this command:
asl -v
asl -v
Michael Shinn
Atomicorp - Security For Everyone
Atomicorp - Security For Everyone
-
- Forum User
- Posts: 6
- Joined: Fri Feb 15, 2019 3:31 am
- Location: Beirut
Re: Long messages being truncated when sent using syslog_out
mikeshinn wrote:Thats pretty old, I dont think we've put out a version of AEO using a version of OSSEC that old. Can you send me the version number for AEO with this command:
asl -v
It says no such command. Only Ossec is installed it seems.
- mikeshinn
- Atomicorp Staff - Site Admin
- Posts: 4149
- Joined: Thu Feb 07, 2008 7:49 pm
- Location: Chantilly, VA
Re: Long messages being truncated when sent using syslog_out
Ah, OK si that sounds like youre just using the open source builds? If so, then you need to grab the latest source code and build from that the binary your using is quite old and it looks like youre using 3.0, whereas the source tree has patches for the upcoming 4.0 release.
If youre using the commercial version, please let me know your system should definitely not be using such an old version of OSSEC.
If youre using the commercial version, please let me know your system should definitely not be using such an old version of OSSEC.
Michael Shinn
Atomicorp - Security For Everyone
Atomicorp - Security For Everyone
-
- Forum User
- Posts: 6
- Joined: Fri Feb 15, 2019 3:31 am
- Location: Beirut
Re: Long messages being truncated when sent using syslog_out
mikeshinn wrote:Ah, OK si that sounds like youre just using the open source builds? If so, then you need to grab the latest source code and build from that the binary your using is quite old and it looks like youre using 3.0, whereas the source tree has patches for the upcoming 4.0 release.
If youre using the commercial version, please let me know your system should definitely not be using such an old version of OSSEC.
We are using the open source version yes. Unfortunately it seems the latest tag is 3.3.0
https://github.com/ossec/ossec-hids