Getting Data In

Multiple props.conf files

jtm7x2
Explorer

I need to change the TRUNCATE= value to a higher one as I'm getting truncate warnings in my events. However, we have numerous props.conf files - several for the different apps, the default, and the one that is pushed to all of our forwarders and indexers from our deployment server. I could manually go in and change them all, but I want to figure out which one takes precedence. The log entry, as far as I can tell, doesn't tell me which app (if it is, in fact, an app) that is causing the truncation issue.

08-14-2012 08:22:51.849 -0700 WARN LineBreakingProcessor - Truncating line because limit of 10000 has been exceeded: 10975

Is it the event that occurred directly before this error?

We were told that the props.conf files are cumulative, but if you've got four different TRUNCATE= values across 10 props.conf files, how do you know which is being used?

Tags (1)
0 Karma

kristian_kolb
Ultra Champion

This is probably a good place to start:

http://docs.splunk.com/Documentation/Splunk/latest/Admin/Wheretofindtheconfigurationfiles

Also, you need to know that truncation of events take place in the parsing phase, which can happen on either a heavy forwarder or an indexer, so there is no need to push such configs to a Universal forwarder. For more information on that subject, see;

http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings

Hope this helps,

Kristian

Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...