Hi Splunk Inc. Team,
I'm experiencing issues with truncation across all sourcetypes "OktaIM2:*" where in most cases only TRUNCATE=250000 can resolve.
I also detected an issue with LINE_BREAKER regex pattern for sourcetype=OktaIM2:group causing logs not to be ingested.
...current pattern defaults to:
([\r\n]+)
and I had to modify to:
(?<=\}\}\})(\, )
Can we please have these issues addressed and a new version cut for this Add-on in splunkbase?
Thank you.