Getting Data In

DB Connect Failed processing http input

m_zandinia
Path Finder

Hi Splunkers

 

I've tried to read some data from MS SQL Server. The data is json like. It works for a while and then I encounter with this message:

 

ERROR HttpInputDataHandler - Failed processing http input, token name=db-connect-http-input, channel=n/a, source_IP=127.0.0.1, reply=6, events_processed=802, http_input_body_size=11904838

ERROR HttpInputDataHandler - Parsing error : While expecting event's raw text: String value too long. valueSize=5246755, maxValueSize=5242880, totalRequestSize=11904838

 

 

After that no data getting in.

Is there any way to increase the maxValueSize?

or my problem is originated from elsewhere

Thanks in advance

Labels (2)
0 Karma
1 Solution

m_zandinia
Path Finder

I could solve my problem with this solution

 

navigate to $SPLUNK_HOME\etc\apps\splunk_httpinput\local

Edit the inputs.conf file and increase the maxEventSize

That's it!

View solution in original post

0 Karma

m_zandinia
Path Finder

I could solve my problem with this solution

 

navigate to $SPLUNK_HOME\etc\apps\splunk_httpinput\local

Edit the inputs.conf file and increase the maxEventSize

That's it!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

How Edge Processor's Durable Queue Works

Edge Processor sits in one of the most consequential places in any Splunk pipeline: between your data sources ...