<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HEC large field value not extracted but is in _raw in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/HEC-large-field-value-not-extracted-but-is-in-raw/m-p/436120#M124316</link>
    <description>&lt;P&gt;When the events are inserted via HEC running a fieldsummary DOES NOT show report field. When the same raw event is input via a file fieldsummary DOES show report field.&lt;/P&gt;</description>
    <pubDate>Tue, 05 Mar 2019 18:12:09 GMT</pubDate>
    <dc:creator>simpkins1958</dc:creator>
    <dc:date>2019-03-05T18:12:09Z</dc:date>
    <item>
      <title>HEC large field value not extracted but is in _raw</title>
      <link>https://community.splunk.com/t5/Splunk-Search/HEC-large-field-value-not-extracted-but-is-in-raw/m-p/436117#M124313</link>
      <description>&lt;P&gt;Have a field in our HEC input that is larger the 10,000 characters. When searching the data input from HEC the field is has not been extracted. It is in _raw and I can pull it out of there. Really would like to be able to have the field extracted.&lt;/P&gt;

&lt;P&gt;props.conf has:&lt;BR /&gt;
TRUNCATE = 0&lt;/P&gt;

&lt;P&gt;I can manually input the same data via a text file and the large field (a blob of JSON text) is extracted and available fine. Just not when input via HEC.&lt;/P&gt;

&lt;P&gt;See screen shots&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/6462i4FDF96ECC89C7C61/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jan 2019 16:30:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/HEC-large-field-value-not-extracted-but-is-in-raw/m-p/436117#M124313</guid>
      <dc:creator>simpkins1958</dc:creator>
      <dc:date>2019-01-29T16:30:23Z</dc:date>
    </item>
    <item>
      <title>Re: HEC large field value not extracted but is in _raw</title>
      <link>https://community.splunk.com/t5/Splunk-Search/HEC-large-field-value-not-extracted-but-is-in-raw/m-p/436118#M124314</link>
      <description>&lt;P&gt;i'll ask the dumb question...is the report field in the "3 more fields" link?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Feb 2019 23:51:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/HEC-large-field-value-not-extracted-but-is-in-raw/m-p/436118#M124314</guid>
      <dc:creator>maciep</dc:creator>
      <dc:date>2019-02-10T23:51:53Z</dc:date>
    </item>
    <item>
      <title>Re: HEC large field value not extracted but is in _raw</title>
      <link>https://community.splunk.com/t5/Splunk-Search/HEC-large-field-value-not-extracted-but-is-in-raw/m-p/436119#M124315</link>
      <description>&lt;P&gt;No the report field is not listed.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Feb 2019 23:56:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/HEC-large-field-value-not-extracted-but-is-in-raw/m-p/436119#M124315</guid>
      <dc:creator>simpkins1958</dc:creator>
      <dc:date>2019-02-10T23:56:37Z</dc:date>
    </item>
    <item>
      <title>Re: HEC large field value not extracted but is in _raw</title>
      <link>https://community.splunk.com/t5/Splunk-Search/HEC-large-field-value-not-extracted-but-is-in-raw/m-p/436120#M124316</link>
      <description>&lt;P&gt;When the events are inserted via HEC running a fieldsummary DOES NOT show report field. When the same raw event is input via a file fieldsummary DOES show report field.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2019 18:12:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/HEC-large-field-value-not-extracted-but-is-in-raw/m-p/436120#M124316</guid>
      <dc:creator>simpkins1958</dc:creator>
      <dc:date>2019-03-05T18:12:09Z</dc:date>
    </item>
    <item>
      <title>Re: HEC large field value not extracted but is in _raw</title>
      <link>https://community.splunk.com/t5/Splunk-Search/HEC-large-field-value-not-extracted-but-is-in-raw/m-p/436121#M124317</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Canyou increase the maxchars in limits.conf and try.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.4/Admin/Limitsconf"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.4/Admin/Limitsconf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Sid&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2019 18:22:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/HEC-large-field-value-not-extracted-but-is-in-raw/m-p/436121#M124317</guid>
      <dc:creator>sdchakraborty</dc:creator>
      <dc:date>2019-03-05T18:22:24Z</dc:date>
    </item>
    <item>
      <title>Re: HEC large field value not extracted but is in _raw</title>
      <link>https://community.splunk.com/t5/Splunk-Search/HEC-large-field-value-not-extracted-but-is-in-raw/m-p/436122#M124318</link>
      <description>&lt;P&gt;If sending into HEC using the event not raw endpoint in JSON.&lt;BR /&gt;
Set KV_MODE = JSON on the props for that sourcetype. NOT auto...&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf?splunkbot"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf?splunkbot&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2019 18:39:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/HEC-large-field-value-not-extracted-but-is-in-raw/m-p/436122#M124318</guid>
      <dc:creator>starcher</dc:creator>
      <dc:date>2019-03-05T18:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: HEC large field value not extracted but is in _raw</title>
      <link>https://community.splunk.com/t5/Splunk-Search/HEC-large-field-value-not-extracted-but-is-in-raw/m-p/436123#M124319</link>
      <description>&lt;P&gt;Adding this to props.conf fixed the issue:&lt;/P&gt;

&lt;P&gt;[nm_MobileDiagnosticsReportData]&lt;BR /&gt;
KV_MODE = json&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:29:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/HEC-large-field-value-not-extracted-but-is-in-raw/m-p/436123#M124319</guid>
      <dc:creator>simpkins1958</dc:creator>
      <dc:date>2020-09-29T23:29:53Z</dc:date>
    </item>
  </channel>
</rss>

