Deployment Architecture

Splunk logs are truncated to 10,000 characters

Madhusri
Engager

Hi,

Splunk logs are truncated to 10,000 characters.

Please let me know TRUNCATE=20,000 need to change in Splunk installed location or forwarder installation location .

Regards,

Madhusri R

Labels (1)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Madhusri,

TRUNCATE is an option of props.conf (for more infos see at https://docs.splunk.com/Documentation/Splunk/8.2.2/Admin/Propsconf)

so you have to put it in your Indexers and (if present) Heavy Forwarders.

Ciao.

Giuseppe

0 Karma

Madhusri
Engager

Hi @gcusello 

 

Could you please provide the indexers location ?

 

Regards,

Madhu

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Madhusri,

you could put props.conf in $SPLUNK_HOME/system/local, but I don't like it.

I hint to create a custom dedicated Technical Add-On (TA), called e.g. TA_Indexers, containing your props.conf and eventual other conf files.

The TA will be located in $SPLUNK_HOME/apps

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...