All Apps and Add-ons

JMS Modular Input - Truncation of events greater than 10,000 chars

rturk
Builder

Greetings!

We have configured the JMS Modular Input to be a durable subscriber to a JMS queue and we're happily retrieving data :thumbs-up:

We are also doing this in a DEV/TEST environment. In this environment, (large) stack traces are sometimes in the JSON payloads which tips the event over 10,000 characters... at which point we see the event become truncated, which breaks the JSON structure and the use of spath :sad-face:

Is there any setting anywhere that would allow me to disable/negate this?

Regards,

RT.

1 Solution

Damien_Dallimor
Ultra Champion

You can set the TRUNCATE parameter in props.conf for your sourcetype to prevent truncation.

As described in this answer.

View solution in original post

Damien_Dallimor
Ultra Champion

You can set the TRUNCATE parameter in props.conf for your sourcetype to prevent truncation.

As described in this answer.

rturk
Builder

Thanks Damien - I think I was having a derr moment as I put the TRUNCATE statement in the inputs.conf... Mea culpa. Thanks again for your help.

0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...