<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Safe TRUNCATE value on json events in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Safe-TRUNCATE-value-on-json-events/m-p/538679#M90261</link>
    <description>&lt;P&gt;What would be a “safe” value for the TRUNCATE option in props.conf?&lt;/P&gt;&lt;P&gt;I have some pretty big json events coming via HEC hitting the _json sourcetype (INDEXED_EXTRACTIONS=json).&lt;/P&gt;</description>
    <pubDate>Thu, 04 Feb 2021 19:50:39 GMT</pubDate>
    <dc:creator>andreibanaru</dc:creator>
    <dc:date>2021-02-04T19:50:39Z</dc:date>
    <item>
      <title>Safe TRUNCATE value on json events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Safe-TRUNCATE-value-on-json-events/m-p/538679#M90261</link>
      <description>&lt;P&gt;What would be a “safe” value for the TRUNCATE option in props.conf?&lt;/P&gt;&lt;P&gt;I have some pretty big json events coming via HEC hitting the _json sourcetype (INDEXED_EXTRACTIONS=json).&lt;/P&gt;</description>
      <pubDate>Thu, 04 Feb 2021 19:50:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Safe-TRUNCATE-value-on-json-events/m-p/538679#M90261</guid>
      <dc:creator>andreibanaru</dc:creator>
      <dc:date>2021-02-04T19:50:39Z</dc:date>
    </item>
    <item>
      <title>Re: Safe TRUNCATE value on json events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Safe-TRUNCATE-value-on-json-events/m-p/538776#M90277</link>
      <description>&lt;P&gt;"Safe" is a relative term.&amp;nbsp; To avoid all event truncations, the "safe" setting is &lt;FONT face="courier new,courier"&gt;TRUNCATE = 0&lt;/FONT&gt;, but that runs the risk of multiple events that are not line-broken correctly being ingested as a single event without warning.&lt;/P&gt;&lt;P&gt;Another "safe" approach is to set TRUNCATE to a reasonable value based on the expected event size plus a margin for error (maybe 10%).&amp;nbsp; If the logs indicate an event was truncated then investigate to see if the line-breaking settings should be changes or if the TRUNCATE setting should be increase.&amp;nbsp; Adjust and repeat.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 14:29:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Safe-TRUNCATE-value-on-json-events/m-p/538776#M90277</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-02-05T14:29:43Z</dc:date>
    </item>
  </channel>
</rss>

