Getting Data In

How to configure Splunk to index a one line JSON file with 55,000 characters?

khhenderson
Path Finder

I have been trying to index a one line JSON file with 55,000 characters in a single line.
Splunk seems to cut it off around 17,000 characters.

My props.conf

AMANDA JSON FILES
[amanda]
INDEXED_EXTRACTIONS = json
KV_MODE = none
TRUNCATE = 0
SHOULD_LINEMERGE = true

andygerber
Path Finder
0 Karma

khhenderson
Path Finder

Changed my limits.conf file
[spath]

number of characters to read from an XML or JSON event when auto extracting

extraction_cutoff = 60000
I'll test and let you know.

0 Karma

khhenderson
Path Finder

I have tested changing the setting in the limits.conf file.
Not Luck.
Could it be the search can only show so many characters?

0 Karma

damianpadden
Loves-to-Learn

hi,
Did you get to the bottom of this. I am in the same situation.

Thanks

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...