Getting Data In

How to truncate events in SplunkWeb

mihenn
Path Finder

Hello,

I have an unusual requirement for Splunk. I have a source that returns error messages from Java applications. These applications process messages from a Kafka cluster. If an error occurs, the message from Kafka is sometimes appended to the error message. These messages are about 5MB in size.

I get the events in Splunk. However, the display of this data is a problem. If I search the corresponding index, I get back these very big events among other smaller ones. These cause SplunkWeb to stop responding.

Is it possible to truncate events in SplunkWeb. The events should be available in the index, but should not be visible in their full length in Splunk.

I have already tried ui-prefs. conf. This allows me to limit the display of events to a certain number of lines via display. events. maxLines. However, this only applies to the preview. The complete event is still included in the HTML code of the page.

Is there any way to limit this data earlier?

Thank you very much.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...