Hey guys,

Just wondering but with the "Non standard syslog message (size too
large)" message, does this mean that OSSEC can't parse the log,
period? Is there any way to increase the limit size so that it *can*
read/parse larger messages? Also, does this only apply to syslog, or
to other logs as well?

The reason is because I'm trying to parse a custom log and it is
pretty huge... would the only other option be to pre-parse the log
first so that it's smaller and then have OSSEC look at the smaller log?

Reply via email to