Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AlexK
New Contributor

FortiAnalyzer : Max size limit in syslog messages , prohibited characters ?

Hello everybody, For testing purpose, we use Solarwinds Log Forwarder in order to send Windows events via syslog to our Fortianalyzer. Those particular messages seem to be truncated in "Log View" (first line only) With another syslog server the messages are OK. Here is an example of a message sent by Log Forwarder : "01-25-2018 11:13:09 Kernel.Notice 127.0.0.1 janv. 25 11:13:09 ********** MSWinEventLog 5 Security 267 jeu. janv. 25 11:12:59 2018 4776 Microsoft-Windows-Security-Auditing N/A Audit Success ********** 14336 L’ordinateur a tenté de valider les informations d’identification d’un compte. Package d’authentification : MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Compte d’ouverture de session : ********** Station de travail source : ********** Code d’erreur : 0x0" Here is the result in FortiAnalyzer (first line only) : 01-25-2018 11:13:09 Kernel.Notice ********** janv. 25 11:13:09 ********** MSWinEventLog 5 Security 267 jeu. janv. 25 11:12:59 2018 4776 Microsoft-Windows-Security-Auditing N/A Audit Success ********** 14336 L’ordinateur a tenté de valider les informations d’identification d’un compte. Is there a maximum message size with Fortianalyzer or prohibited characters (such as line feed etc.) ?

P.S : sorry for my broken english, french dude here

0 REPLIES 0
Labels
Top Kudoed Authors