Getting Data In

Multi-Line event truncated

damianshaw
Engager

Hi all,

I am demoing splunk to see if it's appropriate for the company I work for, one of the problems I have hit is one of the logs I would like it to index has 200+ line XML events. After successfully spending sometime working out how to get it to index the timestamp above the XML and not the timestamps in the XML I have now hit a problem with these events.

When the event hit approx 110 lines / 4026 characters it truncates at that point. Is there some workaround? I was looking at limits.conf but I can't find the right stanza / variable.

Tags (2)
0 Karma

damianshaw
Engager

Turns out it was our own logs that did this, doh!!

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...