<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why am I unable to parse logs that are bigger than 10 KB in size? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-parse-logs-that-are-bigger-than-10-KB-in-size/m-p/382975#M93896</link>
    <description>&lt;P&gt;where need to set this value sendEventMaxSize  ?&lt;/P&gt;</description>
    <pubDate>Wed, 14 Nov 2018 18:33:54 GMT</pubDate>
    <dc:creator>pragycho</dc:creator>
    <dc:date>2018-11-14T18:33:54Z</dc:date>
    <item>
      <title>Why am I unable to parse logs that are bigger than 10 KB in size?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-parse-logs-that-are-bigger-than-10-KB-in-size/m-p/382966#M93887</link>
      <description>&lt;P&gt;Hi All ,&lt;/P&gt;

&lt;P&gt;We are using Splunk 6.6.6 version. Whenever we run a query with the log size of each event more than 10 KB in size, we are unable to parse it. We analyzed our search.log and found the following warnings.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;11-12-2018 17:38:11.475 WARN  SearchOperator:kv - date_hour is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.475 WARN  SearchOperator:kv - date_mday is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.475 WARN  SearchOperator:kv - date_minute is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.475 WARN  SearchOperator:kv - date_month is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.475 WARN  SearchOperator:kv - date_second is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.475 WARN  SearchOperator:kv - date_wday is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.475 WARN  SearchOperator:kv - date_year is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.475 WARN  SearchOperator:kv - date_zone is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.475 WARN  SearchOperator:kv - host is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.475 WARN  SearchOperator:kv - index is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.475 WARN  SearchOperator:kv - linecount is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.475 WARN  SearchOperator:kv - punct is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.475 WARN  SearchOperator:kv - source is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.475 WARN  SearchOperator:kv - sourcetype is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.475 WARN  SearchOperator:kv - splunk_server is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.475 WARN  SearchOperator:kv - splunk_server_group is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.475 WARN  SearchOperator:kv - timeendpos is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.475 WARN  SearchOperator:kv - timestartpos is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.475 WARN  SearchOperator:kv - buildRegexList provided empty conf key, ignoring.
11-12-2018 17:38:11.475 WARN  SearchOperator:kv - date_hour is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.475 WARN  SearchOperator:kv - date_mday is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.476 WARN  SearchOperator:kv - date_minute is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.476 WARN  SearchOperator:kv - date_month is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.476 WARN  SearchOperator:kv - date_second is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.476 WARN  SearchOperator:kv - date_wday is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.476 WARN  SearchOperator:kv - date_year is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.476 WARN  SearchOperator:kv - date_zone is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.476 WARN  SearchOperator:kv - host is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.476 WARN  SearchOperator:kv - index is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.476 WARN  SearchOperator:kv - linecount is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.476 WARN  SearchOperator:kv - punct is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.476 WARN  SearchOperator:kv - source is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.476 WARN  SearchOperator:kv - sourcetype is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.476 WARN  SearchOperator:kv - splunk_server is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.476 WARN  SearchOperator:kv - splunk_server_group is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.476 WARN  SearchOperator:kv - timeendpos is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.476 WARN  SearchOperator:kv - timestartpos is an indexed field, ignoring TOKENIZER
11-12-2018 17:38:11.478 INFO  UserManager - Unwound user context: admin -&amp;gt; NULL
11-12-2018 17:38:11.478 INFO  UserManager - Unwound user context: admin -&amp;gt; NULL
11-12-2018 17:38:11.478 INFO  UserManager - Unwound user context: admin -&amp;gt; NULL
11-12-2018 17:38:11.478 INFO  UserManager - Unwound user context: admin -&amp;gt; NULL
11-12-2018 17:38:11.479 INFO  UserManager - Unwound user context: admin -&amp;gt; NULL
11-12-2018 17:38:11.479 INFO  UserManager - Unwound user context: admin -&amp;gt; NULL
11-12-2018 17:38:11.480 INFO  UserManager - Unwound user context: admin -&amp;gt; NULL
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 12 Nov 2018 18:57:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-parse-logs-that-are-bigger-than-10-KB-in-size/m-p/382966#M93887</guid>
      <dc:creator>PCIIT</dc:creator>
      <dc:date>2018-11-12T18:57:00Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to parse logs that are bigger than 10 KB in size?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-parse-logs-that-are-bigger-than-10-KB-in-size/m-p/382967#M93888</link>
      <description>&lt;P&gt;Those messages are unrelated.&lt;/P&gt;

&lt;P&gt;You can change the limit of how much raw data autokv uses in limits.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[kv]
maxchars = &amp;lt;integer&amp;gt;
* Truncate _raw to this size and then do auto KV.
* Default: 10240 characters
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 12 Nov 2018 23:05:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-parse-logs-that-are-bigger-than-10-KB-in-size/m-p/382967#M93888</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2018-11-12T23:05:24Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to parse logs that are bigger than 10 KB in size?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-parse-logs-that-are-bigger-than-10-KB-in-size/m-p/382968#M93889</link>
      <description>&lt;P&gt;i added in limit.conf&lt;BR /&gt;
[kv]&lt;BR /&gt;
 maxchars = 10240&lt;/P&gt;

&lt;P&gt;but still same issue&lt;/P&gt;</description>
      <pubDate>Tue, 13 Nov 2018 05:12:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-parse-logs-that-are-bigger-than-10-KB-in-size/m-p/382968#M93889</guid>
      <dc:creator>PCIIT</dc:creator>
      <dc:date>2018-11-13T05:12:44Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to parse logs that are bigger than 10 KB in size?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-parse-logs-that-are-bigger-than-10-KB-in-size/m-p/382969#M93890</link>
      <description>&lt;P&gt;what is maximum value for maxchars ?&lt;/P&gt;</description>
      <pubDate>Tue, 13 Nov 2018 05:13:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-parse-logs-that-are-bigger-than-10-KB-in-size/m-p/382969#M93890</guid>
      <dc:creator>PCIIT</dc:creator>
      <dc:date>2018-11-13T05:13:24Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to parse logs that are bigger than 10 KB in size?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-parse-logs-that-are-bigger-than-10-KB-in-size/m-p/382970#M93891</link>
      <description>&lt;P&gt;10240 is the default, not going to change anything by setting that. &lt;/P&gt;</description>
      <pubDate>Tue, 13 Nov 2018 09:03:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-parse-logs-that-are-bigger-than-10-KB-in-size/m-p/382970#M93891</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2018-11-13T09:03:34Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to parse logs that are bigger than 10 KB in size?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-parse-logs-that-are-bigger-than-10-KB-in-size/m-p/382971#M93892</link>
      <description>&lt;P&gt;could you please suggest me  ?what is correct value need to set ?&lt;BR /&gt;
[kv]&lt;BR /&gt;
maxchars = 20480  ---&amp;gt;ok or  need to set high value&lt;/P&gt;</description>
      <pubDate>Tue, 13 Nov 2018 16:21:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-parse-logs-that-are-bigger-than-10-KB-in-size/m-p/382971#M93892</guid>
      <dc:creator>PCIIT</dc:creator>
      <dc:date>2018-11-13T16:21:26Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to parse logs that are bigger than 10 KB in size?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-parse-logs-that-are-bigger-than-10-KB-in-size/m-p/382972#M93893</link>
      <description>&lt;P&gt;That depends on your data.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Nov 2018 17:16:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-parse-logs-that-are-bigger-than-10-KB-in-size/m-p/382972#M93893</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2018-11-13T17:16:24Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to parse logs that are bigger than 10 KB in size?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-parse-logs-that-are-bigger-than-10-KB-in-size/m-p/382973#M93894</link>
      <description>&lt;P&gt;I Think its not the issue with event size, below setting is always set to default unless you specify, which controls the event size.&lt;CODE&gt;sendEventMaxSize = &lt;BR /&gt;
 * The maximum size, in bytes, that an fschange event can be for the input to&lt;BR /&gt;
   send the full event to be indexed. &lt;BR /&gt;
 * Limits the size of event data that the fschange input sends.&lt;BR /&gt;
 * This limits the size of indexed file data.&lt;BR /&gt;
 * Default: -1 (unlimited).&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Nov 2018 23:41:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-parse-logs-that-are-bigger-than-10-KB-in-size/m-p/382973#M93894</guid>
      <dc:creator>pruthvikrishnap</dc:creator>
      <dc:date>2018-11-13T23:41:31Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to parse logs that are bigger than 10 KB in size?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-parse-logs-that-are-bigger-than-10-KB-in-size/m-p/382974#M93895</link>
      <description>&lt;P&gt;using 2 log  file and  total size is 50000 KB . what is ideal value for [kv] ?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Nov 2018 18:25:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-parse-logs-that-are-bigger-than-10-KB-in-size/m-p/382974#M93895</guid>
      <dc:creator>pragycho</dc:creator>
      <dc:date>2018-11-14T18:25:25Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to parse logs that are bigger than 10 KB in size?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-parse-logs-that-are-bigger-than-10-KB-in-size/m-p/382975#M93896</link>
      <description>&lt;P&gt;where need to set this value sendEventMaxSize  ?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Nov 2018 18:33:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-parse-logs-that-are-bigger-than-10-KB-in-size/m-p/382975#M93896</guid>
      <dc:creator>pragycho</dc:creator>
      <dc:date>2018-11-14T18:33:54Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to parse logs that are bigger than 10 KB in size?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-parse-logs-that-are-bigger-than-10-KB-in-size/m-p/382976#M93897</link>
      <description>&lt;P&gt;Are your events 50mb in size, or is your file containing many events 50mb in size? The &lt;CODE&gt;maxchars&lt;/CODE&gt; setting applies to event size, not file size.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Nov 2018 21:06:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-parse-logs-that-are-bigger-than-10-KB-in-size/m-p/382976#M93897</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2018-11-14T21:06:43Z</dc:date>
    </item>
  </channel>
</rss>

