Getting Data In

How to truncate events in SplunkWeb

mihenn
Path Finder

Hello,

I have an unusual requirement for Splunk. I have a source that returns error messages from Java applications. These applications process messages from a Kafka cluster. If an error occurs, the message from Kafka is sometimes appended to the error message. These messages are about 5MB in size.

I get the events in Splunk. However, the display of this data is a problem. If I search the corresponding index, I get back these very big events among other smaller ones. These cause SplunkWeb to stop responding.

Is it possible to truncate events in SplunkWeb. The events should be available in the index, but should not be visible in their full length in Splunk.

I have already tried ui-prefs. conf. This allows me to limit the display of events to a certain number of lines via display. events. maxLines. However, this only applies to the preview. The complete event is still included in the HTML code of the page.

Is there any way to limit this data earlier?

Thank you very much.

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...