All Apps and Add-ons

JMS Modular Input - Truncation of events greater than 10,000 chars

rturk
Builder

Greetings!

We have configured the JMS Modular Input to be a durable subscriber to a JMS queue and we're happily retrieving data :thumbs-up:

We are also doing this in a DEV/TEST environment. In this environment, (large) stack traces are sometimes in the JSON payloads which tips the event over 10,000 characters... at which point we see the event become truncated, which breaks the JSON structure and the use of spath :sad-face:

Is there any setting anywhere that would allow me to disable/negate this?

Regards,

RT.

1 Solution

Damien_Dallimor
Ultra Champion

You can set the TRUNCATE parameter in props.conf for your sourcetype to prevent truncation.

As described in this answer.

View solution in original post

Damien_Dallimor
Ultra Champion

You can set the TRUNCATE parameter in props.conf for your sourcetype to prevent truncation.

As described in this answer.

rturk
Builder

Thanks Damien - I think I was having a derr moment as I put the TRUNCATE statement in the inputs.conf... Mea culpa. Thanks again for your help.

0 Karma
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...