All Apps and Add-ons

Splunk is breaking ASM huge events

joaoreis13
New Member

Hi, my F5 ASM gets some realy huge requests, headers and other fields generating events with more than 64k characters. When that happen, the F5 Big IP breaks the event and when that gets into Splunk it's not recognized as an ASM event, because it's beginning doesn't have the string expected by the application.

Have anyone had the same problem? How do I configure Splunk to get that event correctly parsed and concatenated?

0 Karma

adonio
Ultra Champion

hello there,

looked at the add-on and seems like no TRUNCATE value is set, meaning it will truncate events longer than 10000 bytes, default value for this configuration.
try and set TRUNCATE in props.conf under the matching sourcetype stanza in the add-on
create a new local folder in the TA, create props.conf file and add the relevant stanza and a high value for TRUNCATE
read here to learn more:
http://docs.splunk.com/Documentation/Splunk/7.1.0/Admin/Propsconf

hope it helps

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...