<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is the JSON index field extraction failing with large events (&amp;gt; 10k bytes)? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-JSON-index-field-extraction-failing-with-large-events/m-p/399874#M115897</link>
    <description>&lt;P&gt;We fixed this by explicitly setting&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[json]
KV_MODE = json
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It appears when unset and implicitly using KV mode, this 10k limit is hit.&lt;/P&gt;</description>
    <pubDate>Mon, 13 Aug 2018 17:29:15 GMT</pubDate>
    <dc:creator>ecd</dc:creator>
    <dc:date>2018-08-13T17:29:15Z</dc:date>
    <item>
      <title>Why is the JSON index field extraction failing with large events (&gt; 10k bytes)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-JSON-index-field-extraction-failing-with-large-events/m-p/399871#M115894</link>
      <description>&lt;P&gt;I'm using indexed field extraction to ingest JSON data over the HTTP Event Collector. &lt;/P&gt;

&lt;P&gt;It works great. Except, once the event is &amp;gt; 10k bytes, the fields within the JSON are not indexed automatically. For example, if I submit a 15k event then search for it via &lt;CODE&gt;host&lt;/CODE&gt;, I am able to find it. However, if I search for it via a field within the JSON, it does not come up.&lt;/P&gt;

&lt;P&gt;Is it possible to configure this setting? I haven't seen anything in the documentation yet. I'm still new to this particular functionality&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 03:07:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-JSON-index-field-extraction-failing-with-large-events/m-p/399871#M115894</guid>
      <dc:creator>ecd</dc:creator>
      <dc:date>2018-08-13T03:07:02Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the JSON index field extraction failing with large events (&gt; 10k bytes)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-JSON-index-field-extraction-failing-with-large-events/m-p/399872#M115895</link>
      <description>&lt;P&gt;Do the events appear complete when you search for them via "host"?  Meaning, the JSON does not appear truncated in the event viewer.  I would imagine that you are running up against the default TRUNCATE option for your sourcetype (in props.conf), which by default is set to 10000 bytes.  I would try setting TRUNCATE for your sourcetype higher, and then coming back here if that does not work.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 07:10:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-JSON-index-field-extraction-failing-with-large-events/m-p/399872#M115895</guid>
      <dc:creator>brian_rampley</dc:creator>
      <dc:date>2018-08-13T07:10:15Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the JSON index field extraction failing with large events (&gt; 10k bytes)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-JSON-index-field-extraction-failing-with-large-events/m-p/399873#M115896</link>
      <description>&lt;P&gt;The events do appear and are complete. We identified the issue - I'll add an answer for our fix&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 17:26:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-JSON-index-field-extraction-failing-with-large-events/m-p/399873#M115896</guid>
      <dc:creator>ecd</dc:creator>
      <dc:date>2018-08-13T17:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the JSON index field extraction failing with large events (&gt; 10k bytes)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-JSON-index-field-extraction-failing-with-large-events/m-p/399874#M115897</link>
      <description>&lt;P&gt;We fixed this by explicitly setting&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[json]
KV_MODE = json
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It appears when unset and implicitly using KV mode, this 10k limit is hit.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 17:29:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-JSON-index-field-extraction-failing-with-large-events/m-p/399874#M115897</guid>
      <dc:creator>ecd</dc:creator>
      <dc:date>2018-08-13T17:29:15Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the JSON index field extraction failing with large events (&gt; 10k bytes)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-JSON-index-field-extraction-failing-with-large-events/m-p/399875#M115898</link>
      <description>&lt;P&gt;Hi @ecd, which version of splunk you are using ? i am assuming this stanza was created in any props.conf on splunk that is hosting HEC tokens ?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Feb 2019 12:40:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-JSON-index-field-extraction-failing-with-large-events/m-p/399875#M115898</guid>
      <dc:creator>nm1984splunk</dc:creator>
      <dc:date>2019-02-11T12:40:23Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the JSON index field extraction failing with large events (&gt; 10k bytes)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-JSON-index-field-extraction-failing-with-large-events/m-p/399876#M115899</link>
      <description>&lt;P&gt;Hi Ecd ,&lt;/P&gt;

&lt;P&gt;even i m facing the same issue. can u please tell in where you have configured?(indexder, HF,SH)&lt;/P&gt;

&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2019 06:29:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-JSON-index-field-extraction-failing-with-large-events/m-p/399876#M115899</guid>
      <dc:creator>vasanthi77</dc:creator>
      <dc:date>2019-07-24T06:29:59Z</dc:date>
    </item>
  </channel>
</rss>

