I have been trying to index a one line JSON file with 55,000 characters in a single line.
Splunk seems to cut it off around 17,000 characters.
My props.conf
AMANDA JSON FILES
[amanda]
INDEXED_EXTRACTIONS = json
KV_MODE = none
TRUNCATE = 0
SHOULD_LINEMERGE = true
https://answers.splunk.com/answers/179968/parsing-very-long-json-lines.html
Check out the info in the link above.
Changed my limits.conf file
[spath]
extraction_cutoff = 60000
I'll test and let you know.
I have tested changing the setting in the limits.conf file.
Not Luck.
Could it be the search can only show so many characters?
hi,
Did you get to the bottom of this. I am in the same situation.
Thanks