User: ltex Forumlink: http://kb.monitorware.com/viewtopic.php?p=26346#p26346 Message: ---------- Thanks, Are you sure that rsyslog is forwarding WHOLE data and every string in their syslog to SIEM? In SIEM we are seeing only the data AFTER the timestamp and IP, like it was cutted.