Splunk Search

calculating the truncate value for props.conf ?

kteng2024
Path Finder

Hi,

How to calculate the truncate value ? is it calculated based on the log size and max_events ? if yes , can anyone please explain me in calculating it ?

Thanks

0 Karma

nickhills
Ultra Champion

The TRUNCATE value is in bytes of a single event.

What I tend to do is find the largest event in the logs, and paste it into a decent text editor which reports size.
Then set your truncate value to this + % margin of error.

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...