Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Extend syslogtag limit from 32 characters in rsyslog / add SYSLOG.ident field to syslog forwarding #8316

Open
oldflint89 opened this issue Sep 19, 2024 · 0 comments

Comments

@oldflint89
Copy link

Description

  1. This bug report addresses the issue of the syslogtag being limited to 32 characters in the default rsyslog configuration used by PacketFence. This limitation affects logs with long program names such as:

api-frontend-docker-wrapper[1587
radiusd-load-balancer-docker-wra

  1. There is no SYSLOG.ident field in syslog forwarding. This field would be highly useful for SIEM systems as it is typically used to identify the program or source generating the syslog message. Including SYSLOG.ident not only improves log clarity but also enhances traceability, making it a valuable addition for better log management and monitoring.

Impacts

  1. The default 32-character limit causes these program names to be truncated, making it difficult to identify the exact source of logs.

  2. Without the SYSLOG.ident field, it becomes more difficult to quickly identify the program or source responsible for generating a syslog message.

Environment

• PacketFence Version: 13.1
• OS: Debian 11 (deployed from PacketFence ZEN appliance image)
It must be the same even for newer versions.

Below is a screenshot from the syslog server as proof.
from_syslog_server

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants