<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LineBreakingProcessor - Truncating line because limit of 1000000 bytes has been exceeded with a line length &amp;gt;= 1003520 - data_source=&amp;quot;lsof&amp;quot;, data_host=&amp;quot;gbrdcr10328n02&amp;quot;, data_sourcetype=&amp;quot;lsof&amp;quot; in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/LineBreakingProcessor-Truncating-line-because-limit-of-1000000/m-p/119302#M24771</link>
    <description>&lt;P&gt;as an additional note there are three .conf files that do contain a =1000000 they are&lt;/P&gt;

&lt;P&gt;indexes.conf:maxMetaEntries = 1000000&lt;BR /&gt;
limits.conf:max_chunk_queue_size = 1000000&lt;BR /&gt;
props.conf:TRUNCATE = 1000000&lt;/P&gt;

&lt;P&gt;The TRUNCATE one looks hopeful, but comes from the [kvstore] stanza which I initially thought was referring to certificate, but now I see it is key values - I will try creating a local version to allow &amp;gt; 1000000 and see what occurs.&lt;BR /&gt;
[kvstore]&lt;BR /&gt;
SHOULD_LINEMERGE = false&lt;BR /&gt;
TIMESTAMP_FIELDS = datetime&lt;BR /&gt;
TIME_FORMAT = %m-%d-%Y %H:%M:%S.%l %z&lt;BR /&gt;
INDEXED_EXTRACTIONS = json&lt;BR /&gt;
KV_MODE = none&lt;BR /&gt;
TRUNCATE = 1000000&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 20:01:31 GMT</pubDate>
    <dc:creator>john_howley</dc:creator>
    <dc:date>2020-09-28T20:01:31Z</dc:date>
    <item>
      <title>LineBreakingProcessor - Truncating line because limit of 1000000 bytes has been exceeded with a line length &gt;= 1003520 - data_source="lsof", data_host="gbrdcr10328n02", data_sourcetype="lsof"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/LineBreakingProcessor-Truncating-line-because-limit-of-1000000/m-p/119301#M24770</link>
      <description>&lt;P&gt;I am getting this error in the splunkd.log.&lt;BR /&gt;
i've seen a previous post which talks about the Line Breaking settings within Props.conf, but I don't have that section in any of my props,conf either system or nmon (which is the element being complained about)&lt;BR /&gt;
in the Props.conf I have for NMON in [/apps/splunk-6.2.2-255606/splunk/etc/apps/nmon/default] directory I have the nmon config as &lt;/P&gt;

&lt;H1&gt;nmon config stanza&lt;/H1&gt;

&lt;P&gt;[nmon_config]&lt;/P&gt;

&lt;P&gt;BREAK_ONLY_BEFORE=CONFIG,&lt;BR /&gt;
MAX_EVENTS=100000&lt;BR /&gt;
NO_BINARY_CHECK=1&lt;BR /&gt;
SHOULD_LINEMERGE=true&lt;BR /&gt;
TIME_FORMAT=%d-%b-%Y:%H:%M&lt;BR /&gt;
TIME_PREFIX=CONFIG,&lt;BR /&gt;
TRUNCATE=0&lt;/P&gt;

&lt;P&gt;The Truncate=0 would lead me to beleive, from what I've seen on a previous post, don't truncate, but clearly it is.&lt;/P&gt;

&lt;P&gt;Can anyone suggest which setting might be influencing this please? &lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 20:01:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/LineBreakingProcessor-Truncating-line-because-limit-of-1000000/m-p/119301#M24770</guid>
      <dc:creator>john_howley</dc:creator>
      <dc:date>2020-09-28T20:01:28Z</dc:date>
    </item>
    <item>
      <title>Re: LineBreakingProcessor - Truncating line because limit of 1000000 bytes has been exceeded with a line length &gt;= 1003520 - data_source="lsof", data_host="gbrdcr10328n02", data_sourcetype="lsof"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/LineBreakingProcessor-Truncating-line-because-limit-of-1000000/m-p/119302#M24771</link>
      <description>&lt;P&gt;as an additional note there are three .conf files that do contain a =1000000 they are&lt;/P&gt;

&lt;P&gt;indexes.conf:maxMetaEntries = 1000000&lt;BR /&gt;
limits.conf:max_chunk_queue_size = 1000000&lt;BR /&gt;
props.conf:TRUNCATE = 1000000&lt;/P&gt;

&lt;P&gt;The TRUNCATE one looks hopeful, but comes from the [kvstore] stanza which I initially thought was referring to certificate, but now I see it is key values - I will try creating a local version to allow &amp;gt; 1000000 and see what occurs.&lt;BR /&gt;
[kvstore]&lt;BR /&gt;
SHOULD_LINEMERGE = false&lt;BR /&gt;
TIMESTAMP_FIELDS = datetime&lt;BR /&gt;
TIME_FORMAT = %m-%d-%Y %H:%M:%S.%l %z&lt;BR /&gt;
INDEXED_EXTRACTIONS = json&lt;BR /&gt;
KV_MODE = none&lt;BR /&gt;
TRUNCATE = 1000000&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 20:01:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/LineBreakingProcessor-Truncating-line-because-limit-of-1000000/m-p/119302#M24771</guid>
      <dc:creator>john_howley</dc:creator>
      <dc:date>2020-09-28T20:01:31Z</dc:date>
    </item>
    <item>
      <title>Re: LineBreakingProcessor - Truncating line because limit of 1000000 bytes has been exceeded with a line length &gt;= 1003520 - data_source="lsof", data_host="gbrdcr10328n02", data_sourcetype="lsof"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/LineBreakingProcessor-Truncating-line-because-limit-of-1000000/m-p/119303#M24772</link>
      <description>&lt;P&gt;Adjusting that setting in ..local/props.conf and restarting had no affect - stil lget the same error.&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2015 09:05:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/LineBreakingProcessor-Truncating-line-because-limit-of-1000000/m-p/119303#M24772</guid>
      <dc:creator>john_howley</dc:creator>
      <dc:date>2015-05-21T09:05:31Z</dc:date>
    </item>
    <item>
      <title>Re: LineBreakingProcessor - Truncating line because limit of 1000000 bytes has been exceeded with a line length &gt;= 1003520 - data_source="lsof", data_host="gbrdcr10328n02", data_sourcetype="lsof"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/LineBreakingProcessor-Truncating-line-because-limit-of-1000000/m-p/119304#M24773</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/39969"&gt;@john_howley&lt;/a&gt; : The splunkd error pertains to the sourcetype=lsof as reported in data_sourcetype=lsof. You will need a [lsof] stanza defined in props.conf to apply to these events:&lt;/P&gt;

&lt;P&gt;example:&lt;BR /&gt;
set in $SPLUNK_HOME/etc/system/local/props.conf on all of your indexers:&lt;BR /&gt;
[lsof]&lt;BR /&gt;
TRUNCATE=0&lt;/P&gt;

&lt;P&gt;restart splunk&lt;BR /&gt;
$SPLUNK_HOME/bin&lt;BR /&gt;
./splunk restart&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Use the following attributes to define the length of a line.&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;TRUNCATE = &lt;BR /&gt;
* Change the default maximum line length (in bytes).&lt;BR /&gt;
* Although this is in bytes, line length is rounded down when this would&lt;BR /&gt;
  otherwise land mid-character for multi-byte characters.&lt;BR /&gt;
* Set to 0 if you never want truncation (very long lines are, however, often a sign of&lt;BR /&gt;
  garbage data).&lt;BR /&gt;
* Defaults to 10000 bytes.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 20:01:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/LineBreakingProcessor-Truncating-line-because-limit-of-1000000/m-p/119304#M24773</guid>
      <dc:creator>rphillips_splk</dc:creator>
      <dc:date>2020-09-28T20:01:42Z</dc:date>
    </item>
    <item>
      <title>Re: LineBreakingProcessor - Truncating line because limit of 1000000 bytes has been exceeded with a line length &gt;= 1003520 - data_source="lsof", data_host="gbrdcr10328n02", data_sourcetype="lsof"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/LineBreakingProcessor-Truncating-line-because-limit-of-1000000/m-p/119305#M24774</link>
      <description>&lt;P&gt;Thanks rphillips - that worked..&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2015 07:07:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/LineBreakingProcessor-Truncating-line-because-limit-of-1000000/m-p/119305#M24774</guid>
      <dc:creator>john_howley</dc:creator>
      <dc:date>2015-05-22T07:07:11Z</dc:date>
    </item>
    <item>
      <title>Re: LineBreakingProcessor - Truncating line because limit of 1000000 bytes has been exceeded with a line length &gt;= 1003520 - data_source="lsof", data_host="gbrdcr10328n02", data_sourcetype="lsof"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/LineBreakingProcessor-Truncating-line-because-limit-of-1000000/m-p/119306#M24775</link>
      <description>&lt;P&gt;so , should we do this change on the indexer side or splunk forwarder side?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2017 05:23:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/LineBreakingProcessor-Truncating-line-because-limit-of-1000000/m-p/119306#M24775</guid>
      <dc:creator>Tejkumar451</dc:creator>
      <dc:date>2017-02-09T05:23:07Z</dc:date>
    </item>
  </channel>
</rss>

