<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Truncate logs to 10K for all the sources in SPLUNK (cloud)? Default setting is not applicable for HTTP and TCP l in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Truncate-logs-to-10K-for-all-the-sources-in-SPLUNK-cloud-Default/m-p/545538#M154549</link>
    <description>&lt;P&gt;&lt;SPAN&gt;how to truncate logs to 10K for all the sources in SPLUNK (cloud)? The default setting is not applicable for HTTP and TCP logs. I tried using some regex with sed command but it doesn't work out also there is operator precedence while adding any regex in the prop. conf, so when I add the regex it took that, ignoring the default truncate. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any help in this&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 26 Mar 2021 08:02:28 GMT</pubDate>
    <dc:creator>shilpa155</dc:creator>
    <dc:date>2021-03-26T08:02:28Z</dc:date>
    <item>
      <title>Truncate logs to 10K for all the sources in SPLUNK (cloud)? Default setting is not applicable for HTTP and TCP l</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Truncate-logs-to-10K-for-all-the-sources-in-SPLUNK-cloud-Default/m-p/545538#M154549</link>
      <description>&lt;P&gt;&lt;SPAN&gt;how to truncate logs to 10K for all the sources in SPLUNK (cloud)? The default setting is not applicable for HTTP and TCP logs. I tried using some regex with sed command but it doesn't work out also there is operator precedence while adding any regex in the prop. conf, so when I add the regex it took that, ignoring the default truncate. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any help in this&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 08:02:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Truncate-logs-to-10K-for-all-the-sources-in-SPLUNK-cloud-Default/m-p/545538#M154549</guid>
      <dc:creator>shilpa155</dc:creator>
      <dc:date>2021-03-26T08:02:28Z</dc:date>
    </item>
  </channel>
</rss>

