<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Long json got truncated even though TRUNCATE is set to 0 in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Long-json-got-truncated-even-though-TRUNCATE-is-set-to-0/m-p/140652#M28823</link>
    <description>&lt;P&gt;I have the same problem, I have good results being returned but the truncate statement does not seem to work. One note the { is a special character and should be escaped (\{) if you are actually looking for it.&lt;/P&gt;

&lt;P&gt;I expected to get the whole JSON structure but it is still being chopped yet sourcetyped as the stanza i have defined.&lt;/P&gt;

&lt;P&gt;--- I see the web for stripped the \ so ignore if it happened to you as well - Cheers&lt;/P&gt;</description>
    <pubDate>Wed, 11 Dec 2013 18:54:51 GMT</pubDate>
    <dc:creator>mwk1000</dc:creator>
    <dc:date>2013-12-11T18:54:51Z</dc:date>
    <item>
      <title>Long json got truncated even though TRUNCATE is set to 0</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Long-json-got-truncated-even-though-TRUNCATE-is-set-to-0/m-p/140651#M28822</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I would like to add a log file containing json documents - one json per line.  The json documents are pretty long (longer than 10,000 characters) and I don't want them to get truncated so I set the props.conf as follows.&lt;/P&gt;

&lt;PRE&gt;
NO_BINARY_CHECK = 1
SHOULD_LINEMERGE = false
TRUNCATE = 0
KV_MODE=json
LINE_BREAKER=([\n\r]+)({)
&lt;/PRE&gt;

&lt;P&gt;During data preview, everything looks good. Nothing got truncated at all.  However, once I completed the process and searched for it, the data is truncated to 10,000 characters, so Splunk doesn't interpret it as json.&lt;/P&gt;

&lt;P&gt;I saw the warning in splunkd.log below.&lt;/P&gt;

&lt;PRE&gt;
WARN  LineBreakingProcessor - Truncating line because limit of 10000 has been exceeded with a line length &amp;gt;= 10506 - data_source="/opt/readonly/log-archive/mylogfile.log", data_host="test", data_sourcetype="test"
&lt;/PRE&gt;

&lt;P&gt;Any help would be appreciated.&lt;/P&gt;

&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2013 17:28:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Long-json-got-truncated-even-though-TRUNCATE-is-set-to-0/m-p/140651#M28822</guid>
      <dc:creator>nminale</dc:creator>
      <dc:date>2013-11-13T17:28:13Z</dc:date>
    </item>
    <item>
      <title>Re: Long json got truncated even though TRUNCATE is set to 0</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Long-json-got-truncated-even-though-TRUNCATE-is-set-to-0/m-p/140652#M28823</link>
      <description>&lt;P&gt;I have the same problem, I have good results being returned but the truncate statement does not seem to work. One note the { is a special character and should be escaped (\{) if you are actually looking for it.&lt;/P&gt;

&lt;P&gt;I expected to get the whole JSON structure but it is still being chopped yet sourcetyped as the stanza i have defined.&lt;/P&gt;

&lt;P&gt;--- I see the web for stripped the \ so ignore if it happened to you as well - Cheers&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2013 18:54:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Long-json-got-truncated-even-though-TRUNCATE-is-set-to-0/m-p/140652#M28823</guid>
      <dc:creator>mwk1000</dc:creator>
      <dc:date>2013-12-11T18:54:51Z</dc:date>
    </item>
    <item>
      <title>Re: Long json got truncated even though TRUNCATE is set to 0</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Long-json-got-truncated-even-though-TRUNCATE-is-set-to-0/m-p/140653#M28824</link>
      <description>&lt;P&gt;The search may be truncating it. &lt;BR /&gt;
Perhaps maxvaluesize (limits.conf)&lt;BR /&gt;
See &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.0/Admin/Limitsconf"&gt;http://docs.splunk.com/Documentation/Splunk/6.0/Admin/Limitsconf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Also wanted to note that I found a similar post that helped others here:&lt;BR /&gt;
&lt;A href="http://answers.splunk.com/answers/60064/json-event-truncate0"&gt;http://answers.splunk.com/answers/60064/json-event-truncate0&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2013 19:05:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Long-json-got-truncated-even-though-TRUNCATE-is-set-to-0/m-p/140653#M28824</guid>
      <dc:creator>aelliott</dc:creator>
      <dc:date>2013-12-11T19:05:51Z</dc:date>
    </item>
  </channel>
</rss>

