Hi Team,
i am not able to see the complete event log (one log string )in Splunk Search, some of the text got truncated because of that not able to retrieve the required fields.
This is happening for the log strings whose size is large, please let me know how to avoid this issue?
Thanks in Adavnce
Ravi
I am facing same issue. Can anyone please suggest the solution?
Hi @pallavikarpaklu ... may we know the TRUNCATE vaule in your props.conf file please.
In props.config Truncate=1000000
Length of string in my log file is 38309
But, in splunk string truncates at length 9967
Appreciate any help.
UF ---> indexer or
UF---> HF----> indexer
if HF is yes, then, do you have props.conf at HF or indexer or both?
Take a look at this:
http://splunk-base.splunk.com/answers/4162/size-limit-for-an-event
Hi,
i updated that value in prop.conf in local is this the correct way to change it rite?
Regards
Ravi
Hi ,
i have increased the TRUNCATE value to 250000 and restarted the server but still am not able to see the complete event still spunk truncating. Please help me
Regards
ravi
Was this issue resolved?