<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Logs truncated in Splunk despite line being under the 10000 bytes threshold in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Logs-truncated-in-Splunk-despite-line-being-under-the-10000/m-p/702660#M116224</link>
    <description>&lt;P&gt;Most likely there's some line breaking problem. &amp;nbsp;Documentation is&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/Configureeventlinebreaking" target="_blank" rel="noopener"&gt;Configure event line breaking&lt;/A&gt;&amp;nbsp;(and the entire&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/WhatSplunkcanmonitor#collapseDesktop8" target="_blank" rel="noopener"&gt;Configure event processing&lt;/A&gt;. &amp;nbsp;You would also get better discussion in the forum&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/bd-p/getting-data-in" target="_blank"&gt;Getting Data In&lt;/A&gt;.&lt;/P&gt;</description>
    <pubDate>Thu, 24 Oct 2024 05:42:47 GMT</pubDate>
    <dc:creator>yuanliu</dc:creator>
    <dc:date>2024-10-24T05:42:47Z</dc:date>
    <item>
      <title>Logs truncated in Splunk despite line being under the 10000 bytes threshold</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-truncated-in-Splunk-despite-line-being-under-the-10000/m-p/702611#M116223</link>
      <description>&lt;P&gt;Hi community,&lt;BR /&gt;&lt;BR /&gt;I have observed an issue with the ingestion of the first line in a log file that, at first glance, seemed to have been truncated. Here's a screenshot for reference:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/33191i1A1D2F8A2D0AC57E/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;My apologies for the poor job at blurring the data, but the first event should look like the second event, with a whole lot of data after the highlighted field.&lt;BR /&gt;&lt;BR /&gt;The field DistPoint itself should have a value of "DEPSY.IM2" and, it got, apparently, truncated at such a weird point.&lt;BR /&gt;&lt;BR /&gt;All other subsequent lines in the log were successfully ingested.&lt;BR /&gt;&lt;BR /&gt;There were 3 log files landing on the ingestion point in quick succession - seconds apart, so I am not sure if this could have been the issue.&lt;BR /&gt;&lt;BR /&gt;I was about to update the truncate value for the sourcetype, but all lines in the logs are 3551 bytes, by default.&lt;BR /&gt;&lt;BR /&gt;Any ideas as to what could the problem have been?&lt;BR /&gt;&lt;BR /&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2024 15:34:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-truncated-in-Splunk-despite-line-being-under-the-10000/m-p/702611#M116223</guid>
      <dc:creator>victorcorrea</dc:creator>
      <dc:date>2024-10-23T15:34:40Z</dc:date>
    </item>
    <item>
      <title>Re: Logs truncated in Splunk despite line being under the 10000 bytes threshold</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-truncated-in-Splunk-despite-line-being-under-the-10000/m-p/702660#M116224</link>
      <description>&lt;P&gt;Most likely there's some line breaking problem. &amp;nbsp;Documentation is&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/Configureeventlinebreaking" target="_blank" rel="noopener"&gt;Configure event line breaking&lt;/A&gt;&amp;nbsp;(and the entire&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/WhatSplunkcanmonitor#collapseDesktop8" target="_blank" rel="noopener"&gt;Configure event processing&lt;/A&gt;. &amp;nbsp;You would also get better discussion in the forum&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/bd-p/getting-data-in" target="_blank"&gt;Getting Data In&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2024 05:42:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-truncated-in-Splunk-despite-line-being-under-the-10000/m-p/702660#M116224</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-10-24T05:42:47Z</dc:date>
    </item>
    <item>
      <title>Re: Logs truncated in Splunk despite line being under the 10000 bytes threshold</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-truncated-in-Splunk-despite-line-being-under-the-10000/m-p/702692#M116225</link>
      <description>&lt;P&gt;It might also be the issue with badly/not set EVENT_BREAKER (which is not the same as LINE_BREAKER).&lt;/P&gt;&lt;P&gt;Moving the discussion to Getting Data In.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2024 12:47:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-truncated-in-Splunk-despite-line-being-under-the-10000/m-p/702692#M116225</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-10-24T12:47:47Z</dc:date>
    </item>
    <item>
      <title>Re: Logs truncated in Splunk despite line being under the 10000 bytes threshold</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-truncated-in-Splunk-despite-line-being-under-the-10000/m-p/703190#M116288</link>
      <description>&lt;P&gt;Looks like the issue was with "LINE_MERGE=TRUE" in the props.conf file.&lt;BR /&gt;&lt;BR /&gt;Thank you&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp; and&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33901"&gt;@yuanliu&lt;/a&gt;&amp;nbsp;for chiming in.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 18:37:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-truncated-in-Splunk-despite-line-being-under-the-10000/m-p/703190#M116288</guid>
      <dc:creator>victorcorrea</dc:creator>
      <dc:date>2024-10-30T18:37:27Z</dc:date>
    </item>
  </channel>
</rss>

