Monitoring Splunk

Received metadata string exceeding maxLength

jotne
Path Finder

I do get lots of these message from my index servere on a Splunk Enterprice solution.

 

 

05-06-2021 12:18:08.218 +0200 WARN  MetaData::string - Received metadata string exceeding maxLength -- it will be truncated as an indexed extraction. Only searches scanning _raw will be able to find it as a whole word.

 

 

 source: /opt/splunk/var/log/splunk/splunkd.log

splunk_server: all my index servere

Google does not give me anything.

 

Edit turned on metadata::string debugging and did get more detailed info:

Received metadata string exceeding maxLength length=1642 maxLength=1000

But are still not able to find where to change maxLength for meta data.

 

Labels (1)
0 Karma
Take the 2021 Splunk Career Survey

Help us learn about how Splunk has
impacted your career by taking the 2021 Splunk Career Survey.

Earn $50 in Amazon cash!