<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Palo/Splunk Parsing Issue - Field values are Truncating in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Palo-Splunk-Parsing-Issue-Field-values-are-Truncating/m-p/558063#M158495</link>
    <description>&lt;P&gt;Finally got this all straightened out.&amp;nbsp; Needed to use cef utils for splunk along with a separate syslog destination from my panorama with custom cef events setup for the config section to get what i wanted.&lt;/P&gt;</description>
    <pubDate>Thu, 01 Jul 2021 19:13:11 GMT</pubDate>
    <dc:creator>ghostdog920</dc:creator>
    <dc:date>2021-07-01T19:13:11Z</dc:date>
    <item>
      <title>Palo/Splunk Parsing Issue - Field values are Truncating</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Palo-Splunk-Parsing-Issue-Field-values-are-Truncating/m-p/555850#M157833</link>
      <description>&lt;P&gt;Having a strange issue and not sure what my culprit/problem is.&amp;nbsp; Have a panorama to syslogng to Heavy Forwarder to Indexer with a single search head.&amp;nbsp; I see the parsing (I think) where fields are found and values= but they are truncating.&amp;nbsp; Specifically, my raw event has this in it:&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;before_change_detail=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Emergency&lt;/SPAN&gt; &lt;SPAN class="t"&gt;by&lt;/SPAN&gt; &lt;SPAN class="t"&gt;IP&lt;/SPAN&gt;&lt;SPAN&gt; { &lt;/SPAN&gt;&lt;SPAN class="t"&gt;static&lt;/SPAN&gt;&lt;SPAN&gt; [ ""&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Jim&lt;/SPAN&gt; &lt;SPAN class="t"&gt;CentOS&lt;/SPAN&gt;&lt;SPAN&gt;"" ]; } " &lt;/SPAN&gt;&lt;SPAN class="t"&gt;after_change_detail=Emergency&lt;/SPAN&gt; &lt;SPAN class="t"&gt;by&lt;/SPAN&gt; &lt;SPAN class="t"&gt;IP&lt;/SPAN&gt;&lt;SPAN&gt; { }&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;but when i look at the field values, this is what i get:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ghostdog920_0-1623784274273.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14639iA56CD0F822FCFD19/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ghostdog920_0-1623784274273.png" alt="ghostdog920_0-1623784274273.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas on why my field values are getting cut short?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 19:12:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Palo-Splunk-Parsing-Issue-Field-values-are-Truncating/m-p/555850#M157833</guid>
      <dc:creator>ghostdog920</dc:creator>
      <dc:date>2021-06-15T19:12:02Z</dc:date>
    </item>
    <item>
      <title>Palo/Splunk Parsing Issue - Field values are Truncating</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Palo-Splunk-Parsing-Issue-Field-values-are-Truncating/m-p/558063#M158495</link>
      <description>&lt;P&gt;Finally got this all straightened out.&amp;nbsp; Needed to use cef utils for splunk along with a separate syslog destination from my panorama with custom cef events setup for the config section to get what i wanted.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 19:13:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Palo-Splunk-Parsing-Issue-Field-values-are-Truncating/m-p/558063#M158495</guid>
      <dc:creator>ghostdog920</dc:creator>
      <dc:date>2021-07-01T19:13:11Z</dc:date>
    </item>
  </channel>
</rss>

