Getting Data In

DB Connect Failed processing http input

m_zandinia
Path Finder

Hi Splunkers

 

I've tried to read some data from MS SQL Server. The data is json like. It works for a while and then I encounter with this message:

 

ERROR HttpInputDataHandler - Failed processing http input, token name=db-connect-http-input, channel=n/a, source_IP=127.0.0.1, reply=6, events_processed=802, http_input_body_size=11904838

ERROR HttpInputDataHandler - Parsing error : While expecting event's raw text: String value too long. valueSize=5246755, maxValueSize=5242880, totalRequestSize=11904838

 

 

After that no data getting in.

Is there any way to increase the maxValueSize?

or my problem is originated from elsewhere

Thanks in advance

Labels (2)
0 Karma
1 Solution

m_zandinia
Path Finder

I could solve my problem with this solution

 

navigate to $SPLUNK_HOME\etc\apps\splunk_httpinput\local

Edit the inputs.conf file and increase the maxEventSize

That's it!

View solution in original post

0 Karma

m_zandinia
Path Finder

I could solve my problem with this solution

 

navigate to $SPLUNK_HOME\etc\apps\splunk_httpinput\local

Edit the inputs.conf file and increase the maxEventSize

That's it!

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...