On Tue, 24 Apr 2012, Rainer Gerhards wrote:

looking at these dumps, I don't think the problem is the <190>, I think
the
problem is the three characters before that (Q3. in the text
represnetation),
those start at the same point that the timestamp starts in the last
example.


So the pcap file I just sent shows the receipt of the local7 message (with
priority)
and forwarded message from the rsyslog server's perspective. I hope this
can
show you what you need to know to get this identified.

Looking at the pcap, it looks like the actual content is correct, but the
IP/UDP header is written incorrectly. I don't know yet what happens here, but
it is probably related to the library.

David: do you have any more insight?

not yet.

Is it the case that the IP/UDP header is incorrect, or just that it's different?

David Lang
_______________________________________________
rsyslog mailing list
http://lists.adiscon.net/mailman/listinfo/rsyslog
http://www.rsyslog.com/professional-services/
What's up with rsyslog? Follow https://twitter.com/rgerhards

Reply via email to