<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: truncate logs with syslog in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/truncate-logs-with-syslog/m-p/93214#M19388</link>
    <description>&lt;P&gt;Not sure if this will help, but did you try setting TRUNCATE = 0? Also, you should keep in mind that MAX_EVENTS only take affect if SHOULD_LINEMERGE = true.&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 09:31:13 GMT</pubDate>
    <dc:creator>jbsplunk</dc:creator>
    <dc:date>2020-09-28T09:31:13Z</dc:date>
    <item>
      <title>truncate logs with syslog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/truncate-logs-with-syslog/m-p/93213#M19387</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I'm using an UDP connection with syslog and Splunk. &lt;/P&gt;

&lt;P&gt;My problem is that Splunk only show me the firsts 2072 characters of a log. I try to increase the values of "TRUNCATE" and "MAX_EVENTS" inside the props.conf, but it didn't work.&lt;/P&gt;

&lt;P&gt;Also I checked with Wireshark that the logs are sended correctly with syslog.&lt;/P&gt;

&lt;P&gt;Any suggestions?&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 02 May 2011 07:24:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/truncate-logs-with-syslog/m-p/93213#M19387</guid>
      <dc:creator>torbael</dc:creator>
      <dc:date>2011-05-02T07:24:11Z</dc:date>
    </item>
    <item>
      <title>Re: truncate logs with syslog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/truncate-logs-with-syslog/m-p/93214#M19388</link>
      <description>&lt;P&gt;Not sure if this will help, but did you try setting TRUNCATE = 0? Also, you should keep in mind that MAX_EVENTS only take affect if SHOULD_LINEMERGE = true.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:31:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/truncate-logs-with-syslog/m-p/93214#M19388</guid>
      <dc:creator>jbsplunk</dc:creator>
      <dc:date>2020-09-28T09:31:13Z</dc:date>
    </item>
    <item>
      <title>Re: truncate logs with syslog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/truncate-logs-with-syslog/m-p/93215#M19389</link>
      <description>&lt;P&gt;I was told that Splunk's syslog implementation is 'RFC compliant' so that it only accepts the first 1KB of a syslog message. Maybe you are running into something related to that limitation?&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2011 21:17:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/truncate-logs-with-syslog/m-p/93215#M19389</guid>
      <dc:creator>jaoui</dc:creator>
      <dc:date>2011-05-19T21:17:18Z</dc:date>
    </item>
  </channel>
</rss>

