Fortinet Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
alp
New Contributor

Maximum message length for FortiSiem

Hi everyone,

 

Is there a limitation about a syslog message's length or size in FortiSiem? If there is, how can I change it?

 

 

3 REPLIES 3
Anthony_E
Community Manager
Community Manager

Hello alp,

 

Thank you for using the Community Forum.

I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.

 

Regards,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Hello alp,

 

I have found this documentation. Check page 87:

 

https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/02e00da1-7cee-11e9-81a4-005056...

 

Tell me if it helped.

 

Regards,

Anthony-Fortinet Community Team.
premchanderr
Staff
Staff

Hi @alp , 


Fortisiem can receive Syslog event messages of various sizes, but all Appliances are configured with a default maximum event size.


Messages that are larger than the maximum size of the RFC specification for the TCP and UDP protocol have their event payloads truncated to ensure that Fortisiem can receive the event.
Maximum event size by protocol:
UDP syslog messages should not exceed 1024 bytes
TCP syslog messages should not exceed 8192 bytes.

There is no minimum length for the syslog message. Overall performance would be affected if the syslog size limit is increased, more data sent through, more resources needed to process.

Unfortunately, there is no settings on Fortisiem that can allow to increase size of the packet. If you want to increase the size limit, you need to raise a feature request.

Regards,
Prem Chander R