<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Barracuda WAF (Web Application Firewall) truncating query string to access log and in turn into Splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Barracuda-WAF-Web-Application-Firewall-truncating-query-string/m-p/537822#M90131</link>
    <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Splunk Community - WAF Query String Truncation 2 of 2.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12740iA3628E1587BFA97B/image-size/large?v=v2&amp;amp;px=999" role="button" title="Splunk Community - WAF Query String Truncation 2 of 2.png" alt="Splunk Community - WAF Query String Truncation 2 of 2.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 29 Jan 2021 10:08:18 GMT</pubDate>
    <dc:creator>Maycockk</dc:creator>
    <dc:date>2021-01-29T10:08:18Z</dc:date>
    <item>
      <title>Barracuda WAF (Web Application Firewall) truncating query string to access log and in turn into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Barracuda-WAF-Web-Application-Firewall-truncating-query-string/m-p/537819#M90130</link>
      <description>&lt;P&gt;Good morning fellow Splunkers,&lt;/P&gt;&lt;P&gt;This might be a bit more of a Barracuda WAF question than a Splunk question but perhaps someone on here has overcome it already.&lt;/P&gt;&lt;P&gt;We're writing our Barracuda Access Logs into Splunk and noticed that the query string is coming through truncated. In the context of the WAF passing request through to appropriate location and functioning correctly that's absolutely fine. The writing to access log and in turn into Splunk is where we observe the truncation.&lt;/P&gt;&lt;P&gt;Any thoughts or ideas here?&amp;nbsp;&lt;BR /&gt;We use a custom format string to submit to Splunk as follows:&lt;/P&gt;&lt;P&gt;%t %un %lt %ai %ap %ci %cp %id %cu %m %p %h %v %s %bs %br %rtf %pmf %pf %wmf %u %px %pp %tt %uid &lt;STRONG&gt;%q&lt;/STRONG&gt; %r %c&lt;/P&gt;&lt;P&gt;Appreciate all tips/help here. Instructions are found in the&amp;nbsp;waf_export_logs.pdf and query string is specified by %q above.&lt;BR /&gt;&lt;BR /&gt;See attached pics below.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 10:06:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Barracuda-WAF-Web-Application-Firewall-truncating-query-string/m-p/537819#M90130</guid>
      <dc:creator>Maycockk</dc:creator>
      <dc:date>2021-01-29T10:06:55Z</dc:date>
    </item>
    <item>
      <title>Re: Barracuda WAF (Web Application Firewall) truncating query string to access log and in turn into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Barracuda-WAF-Web-Application-Firewall-truncating-query-string/m-p/537822#M90131</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Splunk Community - WAF Query String Truncation 2 of 2.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12740iA3628E1587BFA97B/image-size/large?v=v2&amp;amp;px=999" role="button" title="Splunk Community - WAF Query String Truncation 2 of 2.png" alt="Splunk Community - WAF Query String Truncation 2 of 2.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 10:08:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Barracuda-WAF-Web-Application-Firewall-truncating-query-string/m-p/537822#M90131</guid>
      <dc:creator>Maycockk</dc:creator>
      <dc:date>2021-01-29T10:08:18Z</dc:date>
    </item>
    <item>
      <title>Re: Barracuda WAF (Web Application Firewall) truncating query string to access log and in turn into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Barracuda-WAF-Web-Application-Firewall-truncating-query-string/m-p/537960#M90170</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228984"&gt;@Maycockk&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If event are truncated at 10K bytes, you may have increase TRUNCATE value in your props.conf at indexer or heavy forwarder. This value is 10K default.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[barracuda_waf_sourcetype]
TRUNCATE = 20000&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Jan 2021 05:21:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Barracuda-WAF-Web-Application-Firewall-truncating-query-string/m-p/537960#M90170</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-01-30T05:21:44Z</dc:date>
    </item>
    <item>
      <title>Re: Barracuda WAF (Web Application Firewall) truncating query string to access log and in turn into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Barracuda-WAF-Web-Application-Firewall-truncating-query-string/m-p/538060#M90186</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;SPAN class=""&gt;&lt;A href="https://community.splunk.com/t5/user/viewprofilepage/user-id/206061" target="_self"&gt;scelikok&lt;/A&gt;,&lt;BR /&gt;&lt;BR /&gt;My gut feeling is this is an issue on the Barracuda side. I believe what's being sent to the access log (which in turn is being forward to Splunk) is truncated at log level. I'm hoping someone has encountered/resolved this specific problem before.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 10:01:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Barracuda-WAF-Web-Application-Firewall-truncating-query-string/m-p/538060#M90186</guid>
      <dc:creator>Maycockk</dc:creator>
      <dc:date>2021-02-01T10:01:38Z</dc:date>
    </item>
  </channel>
</rss>

