<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to handle truncation error in Splunk SDK? in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/How-to-handle-truncation-error-in-Splunk-SDK/m-p/377713#M6220</link>
    <description>&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/788306/cannot-solve-mvexpand-output-will-be-truncated-due.html#answer-787149"&gt;check this splunk answer, same problem is resolved&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 08 Dec 2019 09:14:17 GMT</pubDate>
    <dc:creator>to4kawa</dc:creator>
    <dc:date>2019-12-08T09:14:17Z</dc:date>
    <item>
      <title>How to handle truncation error in Splunk SDK?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/How-to-handle-truncation-error-in-Splunk-SDK/m-p/377711#M6218</link>
      <description>&lt;P&gt;Hi Pals,&lt;/P&gt;

&lt;P&gt;Thank you for viewing my question.&lt;/P&gt;

&lt;P&gt;I am retrieving my data through C# and Splunk SDK. But while extracting the results, I am facing the below truncation issue: &lt;BR /&gt;
&lt;EM&gt;"Command mvexpand output will be truncated at XXXXX results due to excessive memory usage.......... max_mem_usage_mb has been reached"&lt;/EM&gt;. &lt;BR /&gt;
I have added all the required filter before MVEXPAND but then too no luck, So below is my question:&lt;BR /&gt;
1. Currently, I am slicing the timestamp to minutes and extracting the results. But is there any finer way which Splunk recommend?&lt;BR /&gt;
2. Can the &lt;STRONG&gt;output of Splunk SDK&lt;/STRONG&gt; be JSON? If yes, then doing so can have better results?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:51:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/How-to-handle-truncation-error-in-Splunk-SDK/m-p/377711#M6218</guid>
      <dc:creator>waghpra</dc:creator>
      <dc:date>2020-09-29T23:51:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to handle truncation error in Splunk SDK?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/How-to-handle-truncation-error-in-Splunk-SDK/m-p/377712#M6219</link>
      <description>&lt;P&gt;@waghpra, you may check your /default/props.conf in your app.&lt;BR /&gt;
Check - &lt;A href="https://answers.splunk.com/answers/41648/linebreakingprocessor-truncating-line-because-limit-of-10000-has-been-exceeded.html"&gt;https://answers.splunk.com/answers/41648/linebreakingprocessor-truncating-line-because-limit-of-10000-has-been-exceeded.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2019 04:22:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/How-to-handle-truncation-error-in-Splunk-SDK/m-p/377712#M6219</guid>
      <dc:creator>pbankar</dc:creator>
      <dc:date>2019-12-06T04:22:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to handle truncation error in Splunk SDK?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/How-to-handle-truncation-error-in-Splunk-SDK/m-p/377713#M6220</link>
      <description>&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/788306/cannot-solve-mvexpand-output-will-be-truncated-due.html#answer-787149"&gt;check this splunk answer, same problem is resolved&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Dec 2019 09:14:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/How-to-handle-truncation-error-in-Splunk-SDK/m-p/377713#M6220</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2019-12-08T09:14:17Z</dc:date>
    </item>
  </channel>
</rss>

