Does Stream support receiving Syslog that uses Octet-Counting Framing? For example, from the default configuration in Corelight?
Stream does not support Syslog events sent using Octet-Counting Framing. Stream supports Non-Transparent Framing, specifically the
\n trailer character, defined in RFC 6587, section 3.4.2.
Stream also supports the BSD Syslog format as defined in RFC 3164
Although not supported as of version 3.4.1 this feature is on the roadmap. Ticket number: CRIBL-8628 for future reference.