Getting Data In

LineBreakingProcessor - Truncating line because limit of 10000 has been exceeded -Audit.log

jravida
Communicator

Hi folks,

I am encountering this error in the splunkd.log. I've looked on how to increase the truncating limit, but am hesitant to apply it here because it is referencing "/opt/splunk/var/log/splunk/audit.log", which is an internal source as I see it. Where would I change the props.conf's TRUNCATE value and have it only apply to this file?

0 Karma
1 Solution

mcmaster
Communicator

You should be able to add an entry to $SPLUNK_HOME/etc/system/local/props.conf similiar to this:

[source::.../var/log/splunk/audit.log(.\d+)?]
TRUNCATE = 0

which would disable truncation for that log file. This overrides the default TRUNCATE value for this source.

Before:

$SPLUNK_HOME/bin/splunk cmd btool props list 'source::.../var/log/splunk/audit.log' | grep TRUNCATE
TRUNCATE = 10000

After:

$SPLUNK_HOME/bin/splunk cmd btool props list 'source::.../var/log/splunk/audit.log' | grep TRUNCATE
TRUNCATE = 0

View solution in original post

mcmaster
Communicator

You should be able to add an entry to $SPLUNK_HOME/etc/system/local/props.conf similiar to this:

[source::.../var/log/splunk/audit.log(.\d+)?]
TRUNCATE = 0

which would disable truncation for that log file. This overrides the default TRUNCATE value for this source.

Before:

$SPLUNK_HOME/bin/splunk cmd btool props list 'source::.../var/log/splunk/audit.log' | grep TRUNCATE
TRUNCATE = 10000

After:

$SPLUNK_HOME/bin/splunk cmd btool props list 'source::.../var/log/splunk/audit.log' | grep TRUNCATE
TRUNCATE = 0

jravida
Communicator

This did the trick. Thanks for the btool query to verify!

0 Karma

sw5269
New Member

I am having same issue.
It is in a specific class and we have added the TRUNCATE in the $SPLUNK_HOME/etc/deployment_apps//local/props.conf, deployed it and verified it was at destination but still getting thousands of these messages.

0 Karma

AppServices
Explorer

See http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings

This is a great site that shows which servers should contain the correct Splunk configuration files.

In your case, you are settings TRUNCATE (parsing phase) in your props.conf and sending it to your Splunk forwarder server. Based on the above link the only time you should set parsing on a forwarder is when it's a heavy forwarder. Otherwise, you should set your parsing configuration on your indexer.

So, trying adding your TRUNCATE setting in your props.conf on your indexer server and see if that resolves your issue.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...