Sylog message sizing

  • 31 August 2023
  • 2 replies
  • 92 views

Userlevel 2
Badge +1

Hi

What are your opinions on increasing the size of the syslog message.

Increasing syslog message size will potentially have a negative impact on the performance in log collection, normalization and parsing.

On the other hand it is important to be able to extract the necessary information from collected log messages, and some windows evenLog messages have increased over time.

Take for example event ID 4662 ‘An operation was performed on an object’, it can exceed 34000 in message size.

Another example is custom application logs, where developers might have another opinion, of what meaningful logs should contain.

Regards

Hans 

 


2 replies

Userlevel 4
Badge +8

We have increased it to the maximum of 64K to collect and normalize the Windows PowerShell Script Block Logs.

Userlevel 2
Badge +1

Hi Markus

Really interesting - I was concerned that it would put too much stress on the system. But then again, as many of the normalizers are compiled, then it will reduce load.

Do you have any idea of how many large messages is being generated in 24 hours in your installation?

Regards

Hans

Reply