We have experienced messages being truncated in Splunk and other messages in the queue behind the larger message are discarded. Is there a way to configure the max message length for this product? Thanks
Resolved. Set the value of TRUNCATE in props.conf to a value greater than the largest message in the queue.
View solution in original post
Refer to this answer : http://answers.splunk.com/answers/171462/jms-modular-input-truncation-of-events-greater-tha.html