Getting Data In

How to check size allocated to source-type and what is the maximum size of a transaction that sourcetype can hold

MP5591
New Member

How to check size allocated to source-type and what is the maximum size of a transaction that sourcetype can hold

Tags (1)
0 Karma

Sukisen1981
Champion

are you asking size and retention of sourcetype or index?
One index has data size / time to retention bucket roll over policies. It can have multiple source / sourcetypes, that does not matter.
But I am thinking that perhaps you are asking for something else?

0 Karma

MP5591
New Member

@Sukisen1981 -Thanks for responding.

I was asking about sourcetype. How to know the size allocated to sourcetype. Also what is the limit on the size data we pass in a transaction? we see that transaction with 1mB data is not getting logged in

0 Karma

jawaharas
Motivator

Little more detail will be helpful to assist you.

What you mean by transaction with 1 MB data? Is it log file size or single log event size?

Can you post your inputs.conf file config from Universal Forwarder for the sourcetype?

0 Karma

kmorris_splunk
Splunk Employee
Splunk Employee

To @Sukisen1981's point, sourcetype has no size associated with it. You define the size of an index. Sourcetype is simply a way of categorizing your data.

0 Karma

MP5591
New Member

@jawaharas-its single log event of size 1 MB. is there any limit on this .

0 Karma

somesoni2
Revered Legend

A real-life transaction may contain multiple Splunk "events" (based on how the sourcetype is breaking events in your log file. The default size of an event is 10,000 bytes after which an event will be truncated (not dropped fully, just first 10,000 bytes are retained). You can change this by setting up TRUNCATE attribute for your sourcetype. You can refer to following Splunk documentation for information on various sourcetype level attributes:
https://docs.splunk.com/Documentation/Splunk/latest/admin/Propsconf#Line_breaking

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...