I have been trying to index a one line JSON file with 55,000 characters in a single line.
Splunk seems to cut it off around 17,000 characters.
AMANDA JSON FILES [amanda] INDEXED_EXTRACTIONS = json KV_MODE = none TRUNCATE = 0 SHOULD_LINEMERGE = true
Changed my limits.conf file
extraction_cutoff = 60000
I'll test and let you know.
I have tested changing the setting in the limits.conf file.
Could it be the search can only show so many characters?