<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Audit Log Truncate in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Audit-Log-Truncate/m-p/689727#M10223</link>
    <description>&lt;P&gt;"Or is the question more like "shouldn't Splunk never write events longer than 10,000 characters?"&lt;/P&gt;&lt;P&gt;Yes - that would be my question. I assume splunk should know that it would exceed some length. So i dont get why there is a "limit" for internal logs. But yeah, that question has no real "this" or "that". Thanks for the reply&lt;/P&gt;</description>
    <pubDate>Wed, 05 Jun 2024 15:04:38 GMT</pubDate>
    <dc:creator>DanielAmlung</dc:creator>
    <dc:date>2024-06-05T15:04:38Z</dc:date>
    <item>
      <title>Splunk Audit Log Truncate</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Audit-Log-Truncate/m-p/689702#M10221</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;since a couple of days i getting these errors from one of my search heads:&lt;/P&gt;&lt;P&gt;"06-05-2024 14:33:35.300 +0200 WARN LineBreakingProcessor [3959599 parsing] - Truncating line because limit of 10000 bytes has been exceeded with a line length &amp;gt;= 11513 - data_source="/opt/splunk/var/log/splunk/audit.log", data_host="XXX", data_sourcetype="splunk_audit""&lt;/P&gt;&lt;P&gt;As far as i understood, i can set truncate value within the props.conf to a higher value. I just want to understand, why internal logs exceeds the line length. Can someone point me in the right direction why the audit logs exceeds this limit?&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 12:51:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Audit-Log-Truncate/m-p/689702#M10221</guid>
      <dc:creator>DanielAmlung</dc:creator>
      <dc:date>2024-06-05T12:51:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Audit Log Truncate</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Audit-Log-Truncate/m-p/689725#M10222</link>
      <description>&lt;P&gt;The audit log exceeds the limit because Splunk wrote a very long event to the log.&amp;nbsp; Why that happened is impossible to say without knowing more about the event itself.&lt;/P&gt;&lt;P&gt;Or is the question more like "shouldn't Splunk never write events longer than 10,000 characters?"&amp;nbsp; If so, I don't disagree, but prefer Splunk give me the option (by increasing TRUNCATE) to log all of the event rather than cut off what might otherwise be important data.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 14:53:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Audit-Log-Truncate/m-p/689725#M10222</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-06-05T14:53:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Audit Log Truncate</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Audit-Log-Truncate/m-p/689727#M10223</link>
      <description>&lt;P&gt;"Or is the question more like "shouldn't Splunk never write events longer than 10,000 characters?"&lt;/P&gt;&lt;P&gt;Yes - that would be my question. I assume splunk should know that it would exceed some length. So i dont get why there is a "limit" for internal logs. But yeah, that question has no real "this" or "that". Thanks for the reply&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 15:04:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Audit-Log-Truncate/m-p/689727#M10223</guid>
      <dc:creator>DanielAmlung</dc:creator>
      <dc:date>2024-06-05T15:04:38Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Audit Log Truncate</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Audit-Log-Truncate/m-p/689740#M10224</link>
      <description>&lt;P&gt;Ideally, Splunk would know it's creating an event that's too large and modify TRUNCATE accordingly for that sourcetype.&amp;nbsp; For log messages that glob together several pieces of information at run-time (like many audit events), the true size of the event won't be known in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 17:24:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Audit-Log-Truncate/m-p/689740#M10224</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-06-05T17:24:43Z</dc:date>
    </item>
  </channel>
</rss>

