> > looking at these dumps, I don't think the problem is the <190>, I think the > problem is the three characters before that (Q3. in the text represnetation), > those start at the same point that the timestamp starts in the last example. > > > So the pcap file I just sent shows the receipt of the local7 message (with priority) > and forwarded message from the rsyslog server's perspective. I hope this can > show you what you need to know to get this identified.
Looking at the pcap, it looks like the actual content is correct, but the IP/UDP header is written incorrectly. I don't know yet what happens here, but it is probably related to the library. David: do you have any more insight? Rainer _______________________________________________ rsyslog mailing list http://lists.adiscon.net/mailman/listinfo/rsyslog http://www.rsyslog.com/professional-services/ What's up with rsyslog? Follow https://twitter.com/rgerhards

