Getting Data In

DB Connect Failed processing http input

m_zandinia
Explorer

Hi Splunkers

 

I've tried to read some data from MS SQL Server. The data is json like. It works for a while and then I encounter with this message:

 

ERROR HttpInputDataHandler - Failed processing http input, token name=db-connect-http-input, channel=n/a, source_IP=127.0.0.1, reply=6, events_processed=802, http_input_body_size=11904838

ERROR HttpInputDataHandler - Parsing error : While expecting event's raw text: String value too long. valueSize=5246755, maxValueSize=5242880, totalRequestSize=11904838

 

 

After that no data getting in.

Is there any way to increase the maxValueSize?

or my problem is originated from elsewhere

Thanks in advance

Labels (2)
0 Karma
1 Solution

m_zandinia
Explorer

I could solve my problem with this solution

 

navigate to $SPLUNK_HOME\etc\apps\splunk_httpinput\local

Edit the inputs.conf file and increase the maxEventSize

That's it!

View solution in original post

0 Karma

m_zandinia
Explorer

I could solve my problem with this solution

 

navigate to $SPLUNK_HOME\etc\apps\splunk_httpinput\local

Edit the inputs.conf file and increase the maxEventSize

That's it!

View solution in original post

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!