Security

why events breaks after 257line when max_events=10000 ist set?

marcokrueger
Path Finder

I have multi-line (Json) events and have configured the import by

NO_BINARY_CHECK=1 
BREAK_ONLY_BEFORE = ^    { 
KV_MODE = json 
MAX_EVENTS = 10000 
MAX_TIMESTAMP_LOOKAHEAD = 14 
NO_BINARY_CHECK = 1 
SHOULD_LINEMERGE = true 
TIME_PREFIX = "startTime": 
TRUNCATE = 0 
pulldown_type=1

but splunk still breaks the event after 257 lines.

best regards
Marco

Tags (1)
0 Karma

kristian_kolb
Ultra Champion

Hi,

Are you applying the settings in the right place? Could be an issue of the config file precedence and/or where in the deployment (forwarder/indexer phases) the configurations is made.

Plaese see;

http://docs.splunk.com/Documentation/Splunk/latest/Admin/Wheretofindtheconfigurationfiles

http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings

Hope this helps,

Kristian

0 Karma

Ayn
Legend

And you do this on the indexer? Or the forwarder?

0 Karma

marcokrueger
Path Finder

Hi Kristian,
I do it in the $SPLUNK_HOME/etc/system/local/props.conf and it seems that this have the highest priority so I wonder why the MAX_EVENTS = 10000 takes no effect.
Is there any condition for MAX_EVENT lets work?

best regards
Marco

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...