<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why are our logs being truncated to 10,000 characters? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-our-logs-being-truncated-to-10-000-characters/m-p/381920#M20241</link>
    <description>&lt;P&gt;The truncation is happening on the heavy forwarder.  Restart it to apply the props.conf setting and all should be OK.&lt;/P&gt;</description>
    <pubDate>Mon, 12 Nov 2018 12:00:12 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2018-11-12T12:00:12Z</dc:date>
    <item>
      <title>Why are our logs being truncated to 10,000 characters?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-our-logs-being-truncated-to-10-000-characters/m-p/381918#M20239</link>
      <description>&lt;P&gt;I have set... &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[default]
TRUNCATE = 20000
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;...in $SPLUNK_HOME/etc/system/local/props.conf for our search heads (a cluster of 3), indexers (a cluster of 3) and Heavy forwarder.  I have restarted all the search heads and indexers to pick up the change, but we are still getting just as many records where "meta::truncated" is getting set and the log entry is just 10,000 characters.  This then plays havoc with our attempts with downstream searches to parse out JSON values using spath.  Some of the information we need is just not present.&lt;/P&gt;

&lt;P&gt;Do I need to restart the Heavy Forwarder?  Is it where the truncation is occurring?  Are there any data loss implications of stopping the single Heavy Forwarder?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;

&lt;P&gt;David.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Nov 2018 06:09:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-our-logs-being-truncated-to-10-000-characters/m-p/381918#M20239</guid>
      <dc:creator>davidmills</dc:creator>
      <dc:date>2018-11-12T06:09:55Z</dc:date>
    </item>
    <item>
      <title>Re: Why are our logs being truncated to 10,000 characters?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-our-logs-being-truncated-to-10-000-characters/m-p/381919#M20240</link>
      <description>&lt;P&gt;this will be done in test or dev or prod?!?!&lt;/P&gt;</description>
      <pubDate>Mon, 12 Nov 2018 06:42:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-our-logs-being-truncated-to-10-000-characters/m-p/381919#M20240</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2018-11-12T06:42:27Z</dc:date>
    </item>
    <item>
      <title>Re: Why are our logs being truncated to 10,000 characters?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-our-logs-being-truncated-to-10-000-characters/m-p/381920#M20241</link>
      <description>&lt;P&gt;The truncation is happening on the heavy forwarder.  Restart it to apply the props.conf setting and all should be OK.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Nov 2018 12:00:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-our-logs-being-truncated-to-10-000-characters/m-p/381920#M20241</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2018-11-12T12:00:12Z</dc:date>
    </item>
    <item>
      <title>Re: Why are our logs being truncated to 10,000 characters?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-our-logs-being-truncated-to-10-000-characters/m-p/381921#M20242</link>
      <description>&lt;P&gt;That worked - thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Nov 2018 23:16:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-our-logs-being-truncated-to-10-000-characters/m-p/381921#M20242</guid>
      <dc:creator>davidmills</dc:creator>
      <dc:date>2018-11-12T23:16:47Z</dc:date>
    </item>
  </channel>
</rss>

