Getting Data In

Why am I getting the following error from the LineBreakingProcessor: "Truncating line because limit of 10000 bytes has been exceeded?"

swaroopbr
Engager

Hi Team,

I am using Splunk 7.1.1 and i have been getting this error constantly

LineBreakingProcessor - Truncating line because limit of 10000 bytes has been exceeded

As per various Splunk answers, I tried TRUNCATE=0 & TRUNCATE=999999 as well, but none of them worked for me. I had made sure the setting are in the correct props.conf

Any suggestions how do i get rid of this error?

0 Karma

scheng_splunk
Splunk Employee
Splunk Employee

LineBreaking is done as part of parsing pipeline:
http://docs.splunk.com/Documentation/Splunk/7.2.1/Indexer/Howindexingworks#Event_processing_and_the_...

More details about event processing pipelines:
https://wiki.splunk.com/Community:HowIndexingWorks

Please note sometime parsing can be done by the Heavy Forwarder:
http://docs.splunk.com/Documentation/Splunk/7.2.1/Deploy/Componentsofadistributedenvironment#How_com...

If by any chance you have HF doing the parsing, perhaps you should apply relevant props.conf on the Heavy Forwarder.

You may check splunkd.log on relevant Splunk components searching for "truncating" and look for if the particular log is getting truncated due to any setting.

0 Karma

prakash007
Builder

Make sure you have this configs on your indexers...
http://docs.splunk.com/Documentation/Splunk/7.2.1/Admin/Propsconf#Line_breaking

0 Karma

dkeck
Influencer

Did you restart splunkd after changing the props?
Maybe check spelling ?
Please post your conf

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...