See attached screenshot. It looks like the splunk table command displays up to a maximum of 10 values for the generalLedger.generalLedgerCode and caption columns. The raw data is in JSON:
{
"billId":"3558",
"beginDate":"2015-09-01T00:00:00",
"endDate":"2015-10-01T00:00:00",
"bodyLines":
[
{
"caption":"Empress"
"generalLedger": { "generalLedgerCode":"TRAF_NG_SHELL" }
}
{
"caption":"Empress Fuel"
"generalLedger": { "generalLedgerCode":"TRAF_NG_SHELL" }
}
(...and so on...)
]
}
How do I increase or remove this limit?
I switched from "INDEXED_EXTRACTIONS = JSON" to "KV_MODE = json" and can confirm that the problem is fixed.
The problem is with INDEXED_EXTRACTIONS.
I switched from "INDEXED_EXTRACTIONS = JSON" to "KV_MODE = json" and can confirm that the problem is fixed.
The problem is with INDEXED_EXTRACTIONS.
Not really an answer, more of a workaround. The problem with JSON INDEXED_EXTRACTIONS still exists!
How are you decoding the JSON? Show your inputs.conf
and props.conf
files.
inputs.conf on forwarder:
[monitor:///some/path/to/directory]
disabled = false
index=facilities
crcSalt = \
sourcetype = facilities
props.conf on indexer:
[source::/some/path/to/directory/*]
INDEXED_EXTRACTIONS = JSON
TRUNCATE = 100000
SHOULD_LINEMERGE = false
MUST_BREAK_AFTER = ($)