rgerhards at hq
Apr 24, 2012, 3:27 AM
> > looking at these dumps, I don't think the problem is the <190>, I think
Re: rawmessage forwarding doesn't appear to work -- verydetailed
> problem is the three characters before that (Q3. in the text
> those start at the same point that the timestamp starts in the last
> So the pcap file I just sent shows the receipt of the local7 message (with
> and forwarded message from the rsyslog server's perspective. I hope this
> show you what you need to know to get this identified.
Looking at the pcap, it looks like the actual content is correct, but the
IP/UDP header is written incorrectly. I don't know yet what happens here, but
it is probably related to the library.
David: do you have any more insight?
rsyslog mailing list
What's up with rsyslog? Follow https://twitter.com/rgerhards