Getting Data In

Where do I change the maximum Message body length?

gregbo
Communicator

I'm trying to get a large text file ingested using the HEC.  In my searches for the data, I see events that say "Message body length 3169085 greater than maximum allowed (2097152).  Where can I change that maximum?  I can't find any setting that says "Message body length", and I can't find any setting set to 2097152

Labels (2)
0 Karma

Roy_9
Motivator

Keep the truncate limit to 0 on the sourcetype, hopefully it should fix the problem.

0 Karma

gregbo
Communicator

Thanks for the info,  I tried the solution in that article and it made to difference.  My error message is different than the one in that article.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...