<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why are not all application logs getting forwarded to Splunk? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-not-all-application-logs-getting-forwarded-to-Splunk/m-p/373001#M67621</link>
    <description>&lt;P&gt;I have sporadic issues where not all the logs from application logs are getting forwarded to Splunk. I see gaps in logs when i search in Splunk. &lt;/P&gt;

&lt;P&gt;(a) Is Splunk slow catching up with high log volume generated  by application?  If so, how can i prevent this? &lt;BR /&gt;
(b) Could long XML or binary data in the logs cause some of these issues? &lt;/P&gt;

&lt;P&gt;Appreciate your feed back. &lt;/P&gt;</description>
    <pubDate>Wed, 10 May 2017 23:05:04 GMT</pubDate>
    <dc:creator>Sriram</dc:creator>
    <dc:date>2017-05-10T23:05:04Z</dc:date>
    <item>
      <title>Why are not all application logs getting forwarded to Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-not-all-application-logs-getting-forwarded-to-Splunk/m-p/373001#M67621</link>
      <description>&lt;P&gt;I have sporadic issues where not all the logs from application logs are getting forwarded to Splunk. I see gaps in logs when i search in Splunk. &lt;/P&gt;

&lt;P&gt;(a) Is Splunk slow catching up with high log volume generated  by application?  If so, how can i prevent this? &lt;BR /&gt;
(b) Could long XML or binary data in the logs cause some of these issues? &lt;/P&gt;

&lt;P&gt;Appreciate your feed back. &lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2017 23:05:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-not-all-application-logs-getting-forwarded-to-Splunk/m-p/373001#M67621</guid>
      <dc:creator>Sriram</dc:creator>
      <dc:date>2017-05-10T23:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: Why are not all application logs getting forwarded to Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-not-all-application-logs-getting-forwarded-to-Splunk/m-p/373002#M67622</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I believe that long log lines are truncated due to TRUNCATE parameter in props.conf, have a look in /opt/splunk/var/log/splunk/splunkd.log to confirm.&lt;/P&gt;

&lt;P&gt;To disable truncation&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[App_Sourcetype]
TRUNCATE = 0
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;A href="+https://docs.splunk.com/Documentation/Splunk/6.6.0/Data/Configureeventlinebreaking"&gt;As per Splunk docs:&lt;/A&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;TRUNCATE =
Change the default maximum line length (in bytes).
Although this is in bytes, line length is rounded down when this would
otherwise land mid-character for multi-byte characters.
Set to 0 if you never want truncation (very long lines are, however, often a sign of
garbage data).
Defaults to 10000 bytes.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Ahmed&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2017 09:08:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-not-all-application-logs-getting-forwarded-to-Splunk/m-p/373002#M67622</guid>
      <dc:creator>aakwah</dc:creator>
      <dc:date>2017-05-11T09:08:30Z</dc:date>
    </item>
  </channel>
</rss>

