It's a known issue for HEC that for indexed extraction `maxEventSize` is not honored hence max json payload is 512KB.
Splunk 9.0 and above issue is fixed.
It's a known issue for HEC that for indexed extraction `maxEventSize` is not honored hence max json payload is 512KB.
Splunk 9.0 and above issue is fixed.