Getting Data In

Multi-Line event truncated

damianshaw
Engager

Hi all,

I am demoing splunk to see if it's appropriate for the company I work for, one of the problems I have hit is one of the logs I would like it to index has 200+ line XML events. After successfully spending sometime working out how to get it to index the timestamp above the XML and not the timestamps in the XML I have now hit a problem with these events.

When the event hit approx 110 lines / 4026 characters it truncates at that point. Is there some workaround? I was looking at limits.conf but I can't find the right stanza / variable.

Tags (2)
0 Karma

damianshaw
Engager

Turns out it was our own logs that did this, doh!!

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...