What is the best way to get my all the data of a single lined of length 1194646 into splunk ?
My data starts with :
0328-15:34:30.007 [ jnsdnvsvn] ...RECEIVE_NEW_AUTHS ..tradeOrderId=xxx.. NewAuthsReceived .. TradeOrderUpdate ....tradeOrderId=xxx
0328-15:34:31.470 [ lkjnksdjnc] ...RECEIVE_NEW_AUTHS ..tradeOrderId=xxx.. NewAuthsReceived .. TradeOrderUpdate ....tradeOrderId=xxx
Please explain your subject line. Why can you not use
TRUNCATE = 0?
Is this a single event of 1 million characters or are you combining multiple events? If the latter, why?
It's just a single event with 1194646 characters which needs to get into Splunk. I'm missing data in Splunk.
earlier i have 67k characters in a single line and i set TRUNCATE=100000 where I'm able to get all events but now i had ~2 million characters per line. As per one Splunk answers, i noticed that i can't use TRUNCATE=0 link for that below.
So, how i need to get all my 1194646 characters in a single line to get into Splunk.
TRUNCATE=0 is a start. Once you have your events onboarded and can see actual sizes, you can adjust the TRUNCATE setting to something specific that covers all events.
i know actual size/length of a line which is 1194646(single line with multiple characters). that is there anything that i can set it to truncate value to unlimited, where i can't use TRUNCATE=0 anyways is there any other way.