I've tried to read some data from MS SQL Server. The data is json like. It works for a while and then I encounter with this message:
ERROR HttpInputDataHandler - Failed processing http input, token name=db-connect-http-input, channel=n/a, source_IP=127.0.0.1, reply=6, events_processed=802, http_input_body_size=11904838
ERROR HttpInputDataHandler - Parsing error : While expecting event's raw text: String value too long. valueSize=5246755, maxValueSize=5242880, totalRequestSize=11904838
After that no data getting in.
Is there any way to increase the maxValueSize?
or my problem is originated from elsewhere
Thanks in advance
I could solve my problem with this solution
navigate to $SPLUNK_HOME\etc\apps\splunk_httpinput\local
Edit the inputs.conf file and increase the maxEventSize
View solution in original post