Getting Data In
Highlighted

How to configure Splunk to index a one line JSON file with 55,000 characters?

Path Finder

I have been trying to index a one line JSON file with 55,000 characters in a single line.
Splunk seems to cut it off around 17,000 characters.

My props.conf

AMANDA JSON FILES
[amanda]
INDEXED_EXTRACTIONS = json
KV_MODE = none
TRUNCATE = 0
SHOULD_LINEMERGE = true
Highlighted

Re: How to configure Splunk to index a one line JSON file with 55,000 characters?

Path Finder
0 Karma
Highlighted

Re: How to configure Splunk to index a one line JSON file with 55,000 characters?

Path Finder

Changed my limits.conf file
[spath]

number of characters to read from an XML or JSON event when auto extracting

extraction_cutoff = 60000
I'll test and let you know.

0 Karma
Highlighted

Re: How to configure Splunk to index a one line JSON file with 55,000 characters?

Path Finder

I have tested changing the setting in the limits.conf file.
Not Luck.
Could it be the search can only show so many characters?

0 Karma
Highlighted

Re: How to configure Splunk to index a one line JSON file with 55,000 characters?

New Member

hi,
Did you get to the bottom of this. I am in the same situation.

Thanks

0 Karma