Hi All,
I setup one universal forwarder on my windows server and forward the logs to my linux splunk instance, and the events are truncated to 10000.
I tried set the truncate settings in my forwarder, and it doesn’t work at all, here’s my configuration:
E:\services\SplunkUniversalForwarder\etc\apps\Splunk_TA_windows\local\inputs.conf
[monitor://E:\logs]
**TRUNCATE = 0**
disabled = false
Can someone help that?
... View more