<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Escaping / Lifting Message size fixed limit in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/Escaping-Lifting-Message-size-fixed-limit/m-p/381270#M6331</link>
    <description>&lt;P&gt;PS: You can contact Splunk support and put your vote to enhancement request SPL-142222, that I field a few days ago.&lt;BR /&gt;
It's asking to allow having attachments to alert mails compressed, which would most likely reduce their size a lot. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 03 May 2018 17:10:16 GMT</pubDate>
    <dc:creator>xpac</dc:creator>
    <dc:date>2018-05-03T17:10:16Z</dc:date>
    <item>
      <title>Escaping / Lifting Message size fixed limit</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Escaping-Lifting-Message-size-fixed-limit/m-p/381267#M6328</link>
      <description>&lt;P&gt;Good afternoon all,&lt;/P&gt;

&lt;P&gt;Hoping this will be a very quick fix - one of our business users has a scheduled report that when run, produces an email attachment (CSV) of around 12MB in size. However, the email is not generating despite the success of the schedule due to the following:-&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;ERROR:root:(552, '5.3.4 Message size exceeds fixed limit
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I have searched through here and can see varying responses as to how to increase the action.email.maxresults, but this isn't the issue, the issue seems to be a limit of around 10MB on the email / attachment from the resulting report. Our internal mail size limit is 25MB so i'm fairly confident that it is not our internal throttle controls. &lt;/P&gt;

&lt;P&gt;Could someone advise me as to where this default limitation could be lifted / increased? I cannot see an obvious entry within the limits.conf (but leads me to believe i need to therefor add one?).&lt;/P&gt;

&lt;P&gt;Bart&lt;/P&gt;</description>
      <pubDate>Thu, 03 May 2018 12:19:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Escaping-Lifting-Message-size-fixed-limit/m-p/381267#M6328</guid>
      <dc:creator>Barty</dc:creator>
      <dc:date>2018-05-03T12:19:09Z</dc:date>
    </item>
    <item>
      <title>Re: Escaping / Lifting Message size fixed limit</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Escaping-Lifting-Message-size-fixed-limit/m-p/381268#M6329</link>
      <description>&lt;P&gt;Hey, that's actually a message from your mail server.&lt;BR /&gt;
SMTP error 552 relates to the mail being too big. CSVs can get quite big, as they get no compression, and also because of how data attachments in mails work, the actual mail is about 33% bigger than the CSV that's attached to it.&lt;/P&gt;

&lt;P&gt;Long story short - your attachment is too big for your mailserver, so you either have to get your mail server admin to raise that limit, or reduce the size of the report.&lt;/P&gt;

&lt;P&gt;Hope that helps - if it does I'd be happy if you would upvote/accept this answer, so others could profit from it. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 May 2018 12:39:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Escaping-Lifting-Message-size-fixed-limit/m-p/381268#M6329</guid>
      <dc:creator>xpac</dc:creator>
      <dc:date>2018-05-03T12:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: Escaping / Lifting Message size fixed limit</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Escaping-Lifting-Message-size-fixed-limit/m-p/381269#M6330</link>
      <description>&lt;P&gt;Spot on! Thank you for confirming, I'll go back to the business as there is &lt;STRONG&gt;no way&lt;/STRONG&gt; that I will get the mail limit increased&lt;/P&gt;</description>
      <pubDate>Thu, 03 May 2018 14:19:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Escaping-Lifting-Message-size-fixed-limit/m-p/381269#M6330</guid>
      <dc:creator>Barty</dc:creator>
      <dc:date>2018-05-03T14:19:50Z</dc:date>
    </item>
    <item>
      <title>Re: Escaping / Lifting Message size fixed limit</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Escaping-Lifting-Message-size-fixed-limit/m-p/381270#M6331</link>
      <description>&lt;P&gt;PS: You can contact Splunk support and put your vote to enhancement request SPL-142222, that I field a few days ago.&lt;BR /&gt;
It's asking to allow having attachments to alert mails compressed, which would most likely reduce their size a lot. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 May 2018 17:10:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Escaping-Lifting-Message-size-fixed-limit/m-p/381270#M6331</guid>
      <dc:creator>xpac</dc:creator>
      <dc:date>2018-05-03T17:10:16Z</dc:date>
    </item>
  </channel>
</rss>

