Knowledge Management

is there any limit on length of one event in Splunk ?

kumar518g
Explorer

Hi Team,
i am not able to see the complete event log (one log string )in Splunk Search, some of the text got truncated because of that not able to retrieve the required fields.
This is happening for the log strings whose size is large, please let me know how to avoid this issue?

Thanks in Adavnce
Ravi

Tags (2)

pallavikarpaklu
Explorer

I am facing same issue. Can anyone please suggest the solution?

inventsekar
Ultra Champion

Hi @pallavikarpaklu ... may we know the TRUNCATE vaule in your props.conf file please.

0 Karma

pallavikarpaklu
Explorer

In props.config Truncate=1000000

Length of string in my log file is 38309

But, in splunk string truncates at length 9967

Appreciate any help.

inventsekar
Ultra Champion

UF ---> indexer or 

UF---> HF----> indexer

 

if HF is yes, then, do you have props.conf at HF or indexer or both?

0 Karma

isoutamo
SplunkTrust
SplunkTrust
There could be several truncate which can affect here. At least host, source and sourcetype are places where this can defined. Have you already check all of those? Also check was it so that Sosa have priority over source and last is sourcetype.
r. Ismo

jtworzydlo
Path Finder

kumar518g
Explorer

Hi,
i updated that value in prop.conf in local is this the correct way to change it rite?
Regards
Ravi

kumar518g
Explorer

Hi ,
i have increased the TRUNCATE value to 250000 and restarted the server but still am not able to see the complete event still spunk truncating. Please help me
Regards
ravi

ppuru
Path Finder

Was this issue resolved?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...