Knowledge Management

is there any limit on length of one event in Splunk ?

kumar518g
Explorer

Hi Team,
i am not able to see the complete event log (one log string )in Splunk Search, some of the text got truncated because of that not able to retrieve the required fields.
This is happening for the log strings whose size is large, please let me know how to avoid this issue?

Thanks in Adavnce
Ravi

Tags (2)

pallavikarpaklu
Explorer

I am facing same issue. Can anyone please suggest the solution?

inventsekar
SplunkTrust
SplunkTrust

Hi @pallavikarpaklu ... may we know the TRUNCATE vaule in your props.conf file please.

0 Karma

pallavikarpaklu
Explorer

In props.config Truncate=1000000

Length of string in my log file is 38309

But, in splunk string truncates at length 9967

Appreciate any help.

inventsekar
SplunkTrust
SplunkTrust

UF ---> indexer or 

UF---> HF----> indexer

 

if HF is yes, then, do you have props.conf at HF or indexer or both?

0 Karma

isoutamo
SplunkTrust
SplunkTrust
There could be several truncate which can affect here. At least host, source and sourcetype are places where this can defined. Have you already check all of those? Also check was it so that Sosa have priority over source and last is sourcetype.
r. Ismo

jtworzydlo
Path Finder

kumar518g
Explorer

Hi,
i updated that value in prop.conf in local is this the correct way to change it rite?
Regards
Ravi

kumar518g
Explorer

Hi ,
i have increased the TRUNCATE value to 250000 and restarted the server but still am not able to see the complete event still spunk truncating. Please help me
Regards
ravi

ppuru
Path Finder

Was this issue resolved?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...