Getting Data In

Multi-Line event truncated

damianshaw
Engager

Hi all,

I am demoing splunk to see if it's appropriate for the company I work for, one of the problems I have hit is one of the logs I would like it to index has 200+ line XML events. After successfully spending sometime working out how to get it to index the timestamp above the XML and not the timestamps in the XML I have now hit a problem with these events.

When the event hit approx 110 lines / 4026 characters it truncates at that point. Is there some workaround? I was looking at limits.conf but I can't find the right stanza / variable.

Tags (2)
0 Karma

damianshaw
Engager

Turns out it was our own logs that did this, doh!!

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build a No-Code AI Agent at .conf26: Join the AI Agent Buildathon

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...

Level Up Your Workflow: Mastering Splunk Cloud Management via Terraform

Tech Talk Recap   From Chaos to Control: Scaling Splunk Cloud with Infrastructure as Code Managing apps in ...

Forwarder Topology Guidance: Intermediate HF vs Intermediate UF

Why Universal Forwarders Should Not Be Used as Intermediate Forwarders A practical Splunk forwarding topology ...