Skip to content

syslog source: max_length silently drops oversized messages (docs say "truncated"); UDP mode ignores max_length entirely #26439

Description

@paveljanda

A note for the community

  • Please vote on this issue by adding a 👍 reaction to the original issue to help the community and maintainers prioritize this request
  • If you are interested in working on this issue or have submitted a pull request, please leave a comment

Problem

The max_length schema description reads "Messages larger than this are truncated." — but in TCP mode an oversized message is dropped entirely (no event, no truncated version; the source keeps reading). In UDP mode max_length is ignored entirely.

Reproduction (Vector 0.55.0, syslog TCP, max_length: 60): send short → 500-char → short. Only the two short messages become events. The drop is invisible in component metrics (received/sent/discarded unchanged); only vector_component_errors_total{error_code="decoder_frame"} and the ERROR Failed framing bytes. log line record it.

Expected: either truncate as documented, or fix the wording to "drops". Ideally surface drops via a discarded-style metric. Note the generic framing options already have oversized_action (drop|truncate) — the syslog source just doesn't expose it.

Configuration


Version

0.55.0

Debug Output


Example Data

No response

Additional Context

No response

References

No response

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions