<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: logs not complete in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/logs-not-complete/m-p/399917#M6883</link>
    <description>&lt;P&gt;I was under the impression that the logs are getting truncated after 10,000 character limit. But clearly thats not the case. Did you get a chance to look at the splunkd logs and see if you have any errors highlighted?&lt;/P&gt;</description>
    <pubDate>Fri, 17 Aug 2018 16:57:30 GMT</pubDate>
    <dc:creator>nadlurinadluri</dc:creator>
    <dc:date>2018-08-17T16:57:30Z</dc:date>
    <item>
      <title>logs not complete</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/logs-not-complete/m-p/399913#M6879</link>
      <description>&lt;P&gt;Hi , &lt;BR /&gt;
I am having trouble right now on why does the splunk log is not complete/cut , in the past few months logs are coming consistently complete. &lt;BR /&gt;
but now it is cut shows only the header and no information.&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5531i425F364F0761A3DD/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;it came from a server that monitor the logs, &lt;BR /&gt;
Can somebody tell me why this happens ?&lt;BR /&gt;
what to investigate ?&lt;BR /&gt;
Also what is the solution for this problem?&lt;/P&gt;

&lt;P&gt;-thanks in advance&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 04:06:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/logs-not-complete/m-p/399913#M6879</guid>
      <dc:creator>jadengoho</dc:creator>
      <dc:date>2018-08-13T04:06:21Z</dc:date>
    </item>
    <item>
      <title>Re: logs not complete</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/logs-not-complete/m-p/399914#M6880</link>
      <description>&lt;P&gt;I would need to see your inputs.conf, props.conf, and transforms.conf for your particular input, but my first guess would be to investigate your settings in props.conf for your sourcetype.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 06:44:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/logs-not-complete/m-p/399914#M6880</guid>
      <dc:creator>brian_rampley</dc:creator>
      <dc:date>2018-08-13T06:44:48Z</dc:date>
    </item>
    <item>
      <title>Re: logs not complete</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/logs-not-complete/m-p/399915#M6881</link>
      <description>&lt;P&gt;Are the logs getting truncated by any chance?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 22:51:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/logs-not-complete/m-p/399915#M6881</guid>
      <dc:creator>nadlurinadluri</dc:creator>
      <dc:date>2018-08-14T22:51:44Z</dc:date>
    </item>
    <item>
      <title>Re: logs not complete</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/logs-not-complete/m-p/399916#M6882</link>
      <description>&lt;P&gt;1) here is my configuratoin file :&lt;BR /&gt;
Inputs: &lt;CODE&gt;&lt;BR /&gt;
[monitor:///var/log/backup]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
sourcetype = backup:mtx&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;there are no props and transforms set on the whole process.&lt;BR /&gt;
Server(log)-universal forwarder &amp;gt; indexer &amp;gt; search head&lt;/P&gt;

&lt;P&gt;2)Are the logs getting truncated by any chance? &lt;BR /&gt;
- The logs are being cut off in that specific part, &lt;BR /&gt;
there are chances that it would gave as a whole, but most of the time it is missing parts after the &lt;BR /&gt;
"============Backup Summary============"&lt;BR /&gt;
45% of the log it sent are being cut. &lt;BR /&gt;
Still can't figure this out. &lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 23:51:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/logs-not-complete/m-p/399916#M6882</guid>
      <dc:creator>jadengoho</dc:creator>
      <dc:date>2018-08-14T23:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: logs not complete</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/logs-not-complete/m-p/399917#M6883</link>
      <description>&lt;P&gt;I was under the impression that the logs are getting truncated after 10,000 character limit. But clearly thats not the case. Did you get a chance to look at the splunkd logs and see if you have any errors highlighted?&lt;/P&gt;</description>
      <pubDate>Fri, 17 Aug 2018 16:57:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/logs-not-complete/m-p/399917#M6883</guid>
      <dc:creator>nadlurinadluri</dc:creator>
      <dc:date>2018-08-17T16:57:30Z</dc:date>
    </item>
    <item>
      <title>Re: logs not complete</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/logs-not-complete/m-p/399918#M6884</link>
      <description>&lt;P&gt;Does your data contain timestamps?  I don't see any in your sample logs above, but I'm curious is there are timestamps in the missing portions of the data.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Aug 2018 15:07:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/logs-not-complete/m-p/399918#M6884</guid>
      <dc:creator>brian_rampley</dc:creator>
      <dc:date>2018-08-20T15:07:07Z</dc:date>
    </item>
    <item>
      <title>Re: logs not complete</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/logs-not-complete/m-p/399919#M6885</link>
      <description>&lt;P&gt;Looks like the line breaking issue is because there are no settings defined in props.conf and the default settings are not working properly for your data. Can you provide sample events (at least 2) and tell me what the event boundaries are. &lt;/P&gt;</description>
      <pubDate>Mon, 20 Aug 2018 18:06:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/logs-not-complete/m-p/399919#M6885</guid>
      <dc:creator>sudosplunk</dc:creator>
      <dc:date>2018-08-20T18:06:06Z</dc:date>
    </item>
    <item>
      <title>Re: logs not complete</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/logs-not-complete/m-p/399920#M6886</link>
      <description>&lt;P&gt;Thanks all for the help, adding props.conf helps the data to be completed, &lt;BR /&gt;
Still not sure on why does the logs have been cut, but thank's it's working now. &lt;/P&gt;</description>
      <pubDate>Tue, 28 Aug 2018 01:13:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/logs-not-complete/m-p/399920#M6886</guid>
      <dc:creator>jadengoho</dc:creator>
      <dc:date>2018-08-28T01:13:35Z</dc:date>
    </item>
  </channel>
</rss>

