Knowledge Management

What is the maximum length of a tag and an event?

atant
Splunk Employee
Splunk Employee

What is the maximum length of a tag?
What is the maximum length of an event?

Tags (2)
0 Karma

mayurr98
Super Champion

The default event size limit is 10000 characters. You can override this in props.conf as follows

 [yoursourcetypehere]
 TRUNCATE = 0
 MAX_EVENTS = 10000

Setting TRUNCATE to zero means "no truncation". MAX_EVENTS actually sets "the maximum number of lines per event." MAX_EVENTS only applies to multi-line events, but the default is 256 lines. If you are dealing with multi-line events, you may want to set this to a much larger value.

You can put the props.conf file under an application, if it is application-specific, or under /etc/system/local

0 Karma

davpx
Communicator

The maximum length of an event is governed by your TRUNCATE setting in props.conf (default is 10,000 bytes) and can also be manipulated by other parameters.

The maximum length of a tag is not documented as far as I can tell but a quick test tells me its 1024 characters.

0 Karma
Get Updates on the Splunk Community!

Monitoring Postgres with OpenTelemetry

Behind every business-critical application, you’ll find databases. These behind-the-scenes stores power ...

Mastering Synthetic Browser Testing: Pro Tips to Keep Your Web App Running Smoothly

To start, if you're new to synthetic monitoring, I recommend exploring this synthetic monitoring overview. In ...

Splunk Edge Processor | Popular Use Cases to Get Started with Edge Processor

Splunk Edge Processor offers more efficient, flexible data transformation – helping you reduce noise, control ...