Getting Data In

Data Truncated for 1194646 value, where i couldn't use TRUNCATE=0 or TRUNCATE=1194646 in my props

sandeepreddy947
Path Finder

What is the best way to get my all the data of a single lined of length 1194646 into splunk ?

My data starts with :
0328-15:34:30.007 [ jnsdnvsvn] ...RECEIVE_NEW_AUTHS ..tradeOrderId=xxx.. NewAuthsReceived .. TradeOrderUpdate ....tradeOrderId=xxx
0328-15:34:31.470 [ lkjnksdjnc] ...RECEIVE_NEW_AUTHS ..tradeOrderId=xxx.. NewAuthsReceived .. TradeOrderUpdate ....tradeOrderId=xxx

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please explain your subject line. Why can you not use TRUNCATE = 0?
Is this a single event of 1 million characters or are you combining multiple events? If the latter, why?

---
If this reply helps you, Karma would be appreciated.
0 Karma

sandeepreddy947
Path Finder

It's just a single event with 1194646 characters which needs to get into Splunk. I'm missing data in Splunk.
earlier i have 67k characters in a single line and i set TRUNCATE=100000 where I'm able to get all events but now i had ~2 million characters per line. As per one Splunk answers, i noticed that i can't use TRUNCATE=0 link for that below.
"https://answers.splunk.com/answers/90586/can-i-change-truncate-and-max-events-to-unlimited.html"
So, how i need to get all my 1194646 characters in a single line to get into Splunk.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

That answer does not say you can't use TRUNCATE = 0, just that you should very careful about doing so.

---
If this reply helps you, Karma would be appreciated.
0 Karma

sandeepreddy947
Path Finder

Okay, Do we have any other than TRUNCATE=0 in my case then? Or i must set TRUNCATE=0 is the only way to get complete event in splunk

0 Karma

richgalloway
SplunkTrust
SplunkTrust

TRUNCATE=0 is a start. Once you have your events onboarded and can see actual sizes, you can adjust the TRUNCATE setting to something specific that covers all events.

---
If this reply helps you, Karma would be appreciated.
0 Karma

sandeepreddy947
Path Finder

i know actual size/length of a line which is 1194646(single line with multiple characters). that is there anything that i can set it to truncate value to unlimited, where i can't use TRUNCATE=0 anyways is there any other way.

0 Karma
Get Updates on the Splunk Community!

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...

Explore the Latest Educational Offerings from Splunk [January 2025 Updates]

At Splunk Education, we are committed to providing a robust learning experience for all users, regardless of ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...