Getting Data In

Data Truncated for 1194646 value, where i couldn't use TRUNCATE=0 or TRUNCATE=1194646 in my props

sandeepreddy947
Path Finder

What is the best way to get my all the data of a single lined of length 1194646 into splunk ?

My data starts with :
0328-15:34:30.007 [ jnsdnvsvn] ...RECEIVE_NEW_AUTHS ..tradeOrderId=xxx.. NewAuthsReceived .. TradeOrderUpdate ....tradeOrderId=xxx
0328-15:34:31.470 [ lkjnksdjnc] ...RECEIVE_NEW_AUTHS ..tradeOrderId=xxx.. NewAuthsReceived .. TradeOrderUpdate ....tradeOrderId=xxx

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please explain your subject line. Why can you not use TRUNCATE = 0?
Is this a single event of 1 million characters or are you combining multiple events? If the latter, why?

---
If this reply helps you, Karma would be appreciated.
0 Karma

sandeepreddy947
Path Finder

It's just a single event with 1194646 characters which needs to get into Splunk. I'm missing data in Splunk.
earlier i have 67k characters in a single line and i set TRUNCATE=100000 where I'm able to get all events but now i had ~2 million characters per line. As per one Splunk answers, i noticed that i can't use TRUNCATE=0 link for that below.
"https://answers.splunk.com/answers/90586/can-i-change-truncate-and-max-events-to-unlimited.html"
So, how i need to get all my 1194646 characters in a single line to get into Splunk.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

That answer does not say you can't use TRUNCATE = 0, just that you should very careful about doing so.

---
If this reply helps you, Karma would be appreciated.
0 Karma

sandeepreddy947
Path Finder

Okay, Do we have any other than TRUNCATE=0 in my case then? Or i must set TRUNCATE=0 is the only way to get complete event in splunk

0 Karma

richgalloway
SplunkTrust
SplunkTrust

TRUNCATE=0 is a start. Once you have your events onboarded and can see actual sizes, you can adjust the TRUNCATE setting to something specific that covers all events.

---
If this reply helps you, Karma would be appreciated.
0 Karma

sandeepreddy947
Path Finder

i know actual size/length of a line which is 1194646(single line with multiple characters). that is there anything that i can set it to truncate value to unlimited, where i can't use TRUNCATE=0 anyways is there any other way.

0 Karma
Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...