Deployment Architecture

Data truncated to 100kb only

mufthmu
Path Finder

I have edited the props.conf file of the indexer and UF to the following:

[sourcetype]
TRUNCATE=0
MAX_EVENTS=10000

but nothing works.
According to this thread https://answers.splunk.com/answers/155691/why-are-larger-events-are-truncated-10000-bytes.html ,
There is heavy forwarder involved. How do I know if my data flows thru a heavy forwarder before it reaches the indexer?
I have researched on this for ~4hours and still no luck
thanks!

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

To find out if the HF is involved, 1) check the outputs.conf on the UF to see if output goes to the HF; 2) check inputs.conf on the HF to see if the sourcetype in question is reference.

Belt-and-suspenders approach: put the props.conf on the HF anyway. It won't hurt.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

mufthmu
Path Finder

I figured out the issue. I just simply needed to restart the forwarder and the indexer from the bin.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

To find out if the HF is involved, 1) check the outputs.conf on the UF to see if output goes to the HF; 2) check inputs.conf on the HF to see if the sourcetype in question is reference.

Belt-and-suspenders approach: put the props.conf on the HF anyway. It won't hurt.

---
If this reply helps you, Karma would be appreciated.

mufthmu
Path Finder

Thanks @richgalloway , This actually answered the question.
There is no HF involved in the data flow. However, Splunk still does not respond to the props.conf file that I updated both in Indexer AND the UF itself.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...