Getting Data In

Why am I getting the following error from the LineBreakingProcessor: "Truncating line because limit of 10000 bytes has been exceeded?"

swaroopbr
Engager

Hi Team,

I am using Splunk 7.1.1 and i have been getting this error constantly

LineBreakingProcessor - Truncating line because limit of 10000 bytes has been exceeded

As per various Splunk answers, I tried TRUNCATE=0 & TRUNCATE=999999 as well, but none of them worked for me. I had made sure the setting are in the correct props.conf

Any suggestions how do i get rid of this error?

0 Karma

scheng_splunk
Splunk Employee
Splunk Employee

LineBreaking is done as part of parsing pipeline:
http://docs.splunk.com/Documentation/Splunk/7.2.1/Indexer/Howindexingworks#Event_processing_and_the_...

More details about event processing pipelines:
https://wiki.splunk.com/Community:HowIndexingWorks

Please note sometime parsing can be done by the Heavy Forwarder:
http://docs.splunk.com/Documentation/Splunk/7.2.1/Deploy/Componentsofadistributedenvironment#How_com...

If by any chance you have HF doing the parsing, perhaps you should apply relevant props.conf on the Heavy Forwarder.

You may check splunkd.log on relevant Splunk components searching for "truncating" and look for if the particular log is getting truncated due to any setting.

0 Karma

prakash007
Builder

Make sure you have this configs on your indexers...
http://docs.splunk.com/Documentation/Splunk/7.2.1/Admin/Propsconf#Line_breaking

0 Karma

dkeck
Influencer

Did you restart splunkd after changing the props?
Maybe check spelling ?
Please post your conf

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...