Knowledge Management

is there any limit on length of one event in Splunk ?

kumar518g
Explorer

Hi Team,
i am not able to see the complete event log (one log string )in Splunk Search, some of the text got truncated because of that not able to retrieve the required fields.
This is happening for the log strings whose size is large, please let me know how to avoid this issue?

Thanks in Adavnce
Ravi

Tags (2)

pallavikarpaklu
Explorer

I am facing same issue. Can anyone please suggest the solution?

inventsekar
SplunkTrust
SplunkTrust

Hi @pallavikarpaklu ... may we know the TRUNCATE vaule in your props.conf file please.

0 Karma

pallavikarpaklu
Explorer

In props.config Truncate=1000000

Length of string in my log file is 38309

But, in splunk string truncates at length 9967

Appreciate any help.

inventsekar
SplunkTrust
SplunkTrust

UF ---> indexer or 

UF---> HF----> indexer

 

if HF is yes, then, do you have props.conf at HF or indexer or both?

0 Karma

isoutamo
SplunkTrust
SplunkTrust
There could be several truncate which can affect here. At least host, source and sourcetype are places where this can defined. Have you already check all of those? Also check was it so that Sosa have priority over source and last is sourcetype.
r. Ismo

jtworzydlo
Path Finder

kumar518g
Explorer

Hi,
i updated that value in prop.conf in local is this the correct way to change it rite?
Regards
Ravi

kumar518g
Explorer

Hi ,
i have increased the TRUNCATE value to 250000 and restarted the server but still am not able to see the complete event still spunk truncating. Please help me
Regards
ravi

ppuru
Path Finder

Was this issue resolved?

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...