All Apps and Add-ons

Kafka modular input message is trimmed if message is longer, where can I change that ?

kraveruk
Explorer

Hey

I am pulling data from kafka topic, and some larger message jsons are being cut after X characters.

Because of that json format is incomplete and splunk does not recognise event as json type.

Can you please let me know where can I change message/event size >

Thanks

1 Solution

Damien_Dallimor
Ultra Champion

In props.conf for your sourcetype , update the TRUNCATE value.

http://docs.splunk.com/Documentation/Splunk/6.2.3/Admin/Propsconf

View solution in original post

Damien_Dallimor
Ultra Champion

In props.conf for your sourcetype , update the TRUNCATE value.

http://docs.splunk.com/Documentation/Splunk/6.2.3/Admin/Propsconf

tmagdanski
Engager

Fantastic, worked like a charm !

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...