Deployment Architecture

Splunk logs are truncated to 10,000 characters

Madhusri
Engager

Hi,

Splunk logs are truncated to 10,000 characters.

Please let me know TRUNCATE=20,000 need to change in Splunk installed location or forwarder installation location .

Regards,

Madhusri R

Labels (1)
Tags (1)
0 Karma

gcusello
Legend

Hi @Madhusri,

TRUNCATE is an option of props.conf (for more infos see at https://docs.splunk.com/Documentation/Splunk/8.2.2/Admin/Propsconf)

so you have to put it in your Indexers and (if present) Heavy Forwarders.

Ciao.

Giuseppe

0 Karma

Madhusri
Engager

Hi @gcusello 

 

Could you please provide the indexers location ?

 

Regards,

Madhu

0 Karma

gcusello
Legend

Hi @Madhusri,

you could put props.conf in $SPLUNK_HOME/system/local, but I don't like it.

I hint to create a custom dedicated Technical Add-On (TA), called e.g. TA_Indexers, containing your props.conf and eventual other conf files.

The TA will be located in $SPLUNK_HOME/apps

Ciao.

Giuseppe

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!