<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: logs being cutoff in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/logs-being-cutoff/m-p/237893#M46217</link>
    <description>&lt;P&gt;I do not have a local props.conf file, just the default props.conf.&lt;/P&gt;</description>
    <pubDate>Thu, 10 Mar 2016 13:51:29 GMT</pubDate>
    <dc:creator>ralphw_SAIC</dc:creator>
    <dc:date>2016-03-10T13:51:29Z</dc:date>
    <item>
      <title>logs being cutoff</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/logs-being-cutoff/m-p/237887#M46211</link>
      <description>&lt;P&gt;Running Splunk Enterprise and Splunkforwarder, both on RHEL, and we are having issues with the front portion of some logs being cutoff while the back half remains and gets indexed. The datetime stamp and server name remains, but then the front half is removed. This occurs randomly for different events.&lt;/P&gt;

&lt;P&gt;This is an example from the same server and timestamp:&lt;BR /&gt;
&lt;STRONG&gt;From localhost&lt;BR /&gt;
audispd: node=localhost type=SYSCALL msg=audit(1457382989.281:3703928): arch=c000003e syscall=91 success=yes exit=0 a0=3 a1=100 a2=0 a3=7fffdedde310 items=1 ppid=2866 pid=2881 auid=4094 uid=4094 gid=518&lt;BR /&gt;
8 euid=4094 suid=4094 fsuid=4094 egid=5188 sgid=5188 fsgid=5188 tty=(none) ses=11541 comm="betaGraph.ksh" exe="/bin/ksh93" key=(null)&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;From Splunk&lt;BR /&gt;
=0 a3=7fffdeddec90 items=1 ppid=2866 pid=2881 auid=4094 uid=4094 gid=5188 euid=4094 suid=4094 fsuid=4094 egid=5188 sgid=5188 fsgid=5188 tty=(none) ses=11541 comm="betaGraph.ksh" exe="/bin/ksh93" key=(null)&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2016 14:58:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/logs-being-cutoff/m-p/237887#M46211</guid>
      <dc:creator>ralphw_SAIC</dc:creator>
      <dc:date>2016-03-08T14:58:51Z</dc:date>
    </item>
    <item>
      <title>Re: logs being cutoff</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/logs-being-cutoff/m-p/237888#M46212</link>
      <description>&lt;P&gt;So these are log files from the same server, some of the events are being cutoff while other events are correct? Can you see if they have different sourcetypes? If so then you will need to edit your &lt;CODE&gt;inputs.conf&lt;/CODE&gt; and change the sourcetype or edit your &lt;CODE&gt;props.conf&lt;/CODE&gt; and add the linebreaking for that other sourcetype &lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2016 16:20:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/logs-being-cutoff/m-p/237888#M46212</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2016-03-08T16:20:39Z</dc:date>
    </item>
    <item>
      <title>Re: logs being cutoff</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/logs-being-cutoff/m-p/237889#M46213</link>
      <description>&lt;P&gt;There are multiples of these type logs in /var/log/messages. The only difference is the timestamp on them. Some come through ok and some get the leading portion cutoff.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2016 12:45:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/logs-being-cutoff/m-p/237889#M46213</guid>
      <dc:creator>ralphw_SAIC</dc:creator>
      <dc:date>2016-03-09T12:45:33Z</dc:date>
    </item>
    <item>
      <title>Re: logs being cutoff</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/logs-being-cutoff/m-p/237890#M46214</link>
      <description>&lt;P&gt;Go into Splunk and compare the events which are being cutoff vs the events that are not being cutoff. When doing this comparison, look at the sourcetypes (There should be a pre-extracted field called sourcetype). If the sourcetypes are different then its getting cutoff when being indexed. You can fix this by modifying your &lt;CODE&gt;props.conf&lt;/CODE&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2016 15:17:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/logs-being-cutoff/m-p/237890#M46214</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2016-03-09T15:17:16Z</dc:date>
    </item>
    <item>
      <title>Re: logs being cutoff</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/logs-being-cutoff/m-p/237891#M46215</link>
      <description>&lt;P&gt;They are both the same sourcetype, linux_messages_syslog.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:04:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/logs-being-cutoff/m-p/237891#M46215</guid>
      <dc:creator>ralphw_SAIC</dc:creator>
      <dc:date>2020-09-29T09:04:16Z</dc:date>
    </item>
    <item>
      <title>Re: logs being cutoff</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/logs-being-cutoff/m-p/237892#M46216</link>
      <description>&lt;P&gt;Can you post your &lt;CODE&gt;props.conf&lt;/CODE&gt; stanza? &lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2016 21:23:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/logs-being-cutoff/m-p/237892#M46216</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2016-03-09T21:23:02Z</dc:date>
    </item>
    <item>
      <title>Re: logs being cutoff</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/logs-being-cutoff/m-p/237893#M46217</link>
      <description>&lt;P&gt;I do not have a local props.conf file, just the default props.conf.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2016 13:51:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/logs-being-cutoff/m-p/237893#M46217</guid>
      <dc:creator>ralphw_SAIC</dc:creator>
      <dc:date>2016-03-10T13:51:29Z</dc:date>
    </item>
    <item>
      <title>Re: logs being cutoff</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/logs-being-cutoff/m-p/237894#M46218</link>
      <description>&lt;P&gt;Hey @ralphw_SAIC ... You got any solution on this? I am facing the same issue, some random logs are being cutoff intermittently from the start.&lt;BR /&gt;
Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 06:57:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/logs-being-cutoff/m-p/237894#M46218</guid>
      <dc:creator>rosplunk07</dc:creator>
      <dc:date>2020-01-29T06:57:37Z</dc:date>
    </item>
  </channel>
</rss>

