Can anyone tell me why I’m getting different data in two eve logs I have setup?
I have the following log outputs configured:
filetype: unix_dgram #regular|syslog|unix_dgram|unix_stream|redis
filetype: regular #regular|syslog|unix_dgram|unix_stream|redis
I also have logging of payload enabled as follows:
payload: yes # enable dumping payload in Base64
The payload data appears in the .json log as intended but when I monitor data sent to the socket I don’t see the payload here.
Why would this be?
This seems to work fine for me using 5.0.3 (and git master). Two thoughts come to mind:
- The indentation of your yaml might be off, please double check.
- Could the be getting truncated? Are you able to try unix_stream?
Indentation was off - Thanks
Apologies I was mistaken, the same behaviour remains.
This is actually the preferred behaviour as I have no need to send payload data to the socket. I just can’t understand how I’ve managed to accomplish it
Is it actually possible to configure this behaviour or does the addition of the payload configuration apply globally to all configured eve outputs?
Yes. With this config I have the payload being logged to a file, but not logged to the socket: