Deployment Architecture

Splunk logs are truncated to 10,000 characters

Madhusri
Engager

Hi,

Splunk logs are truncated to 10,000 characters.

Please let me know TRUNCATE=20,000 need to change in Splunk installed location or forwarder installation location .

Regards,

Madhusri R

Labels (1)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Madhusri,

TRUNCATE is an option of props.conf (for more infos see at https://docs.splunk.com/Documentation/Splunk/8.2.2/Admin/Propsconf)

so you have to put it in your Indexers and (if present) Heavy Forwarders.

Ciao.

Giuseppe

0 Karma

Madhusri
Engager

Hi @gcusello 

 

Could you please provide the indexers location ?

 

Regards,

Madhu

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Madhusri,

you could put props.conf in $SPLUNK_HOME/system/local, but I don't like it.

I hint to create a custom dedicated Technical Add-On (TA), called e.g. TA_Indexers, containing your props.conf and eventual other conf files.

The TA will be located in $SPLUNK_HOME/apps

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...