Hey
I am pulling data from kafka topic, and some larger message jsons are being cut after X characters.
Because of that json format is incomplete and splunk does not recognise event as json type.
Can you please let me know where can I change message/event size >
Thanks
In props.conf for your sourcetype , update the TRUNCATE value.
http://docs.splunk.com/Documentation/Splunk/6.2.3/Admin/Propsconf
In props.conf for your sourcetype , update the TRUNCATE value.
http://docs.splunk.com/Documentation/Splunk/6.2.3/Admin/Propsconf
Fantastic, worked like a charm !