Getting Data In

How to configure Splunk to index a one line JSON file with 55,000 characters?

khhenderson
Path Finder

I have been trying to index a one line JSON file with 55,000 characters in a single line.
Splunk seems to cut it off around 17,000 characters.

My props.conf

AMANDA JSON FILES
[amanda]
INDEXED_EXTRACTIONS = json
KV_MODE = none
TRUNCATE = 0
SHOULD_LINEMERGE = true

andygerber
Path Finder
0 Karma

khhenderson
Path Finder

Changed my limits.conf file
[spath]

number of characters to read from an XML or JSON event when auto extracting

extraction_cutoff = 60000
I'll test and let you know.

0 Karma

khhenderson
Path Finder

I have tested changing the setting in the limits.conf file.
Not Luck.
Could it be the search can only show so many characters?

0 Karma

damianpadden
Observer

hi,
Did you get to the bottom of this. I am in the same situation.

Thanks

0 Karma
Get Updates on the Splunk Community!

Financial Services Industry Use Cases, ITSI Best Practices, and More New Articles ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Splunk Federated Analytics for Amazon Security Lake

Thursday, November 21, 2024  |  11AM PT / 2PM ET Register Now Join our session to see the technical ...

Splunk With AppDynamics - Meet the New IT (And Engineering) Couple

Wednesday, November 20, 2024  |  10AM PT / 1PM ET Register Now Join us in this session to learn all about ...