We are having a problem with importing all of our data fields because we are only getting the first 50 fields using version 6.
If someone could help me out with this I would greatly appreciate it.
Thank you,
Seth Wilhoite
Hi,
This is a kv limit in default Splunk configuration.
Edit your $SPLUNK_HOME/etc/system/local/limits.conf and set: (see your default/limits.conf for the full section)
[kv]
# maximum number of keys auto kv can generate
limit = 50
To a value that would feet your need.
Restart Splunk and re-index your data.
I had the same issue, took me some time to understand and find that 🙂