Security

why events breaks after 257line when max_events=10000 ist set?

marcokrueger
Path Finder

I have multi-line (Json) events and have configured the import by

NO_BINARY_CHECK=1 
BREAK_ONLY_BEFORE = ^    { 
KV_MODE = json 
MAX_EVENTS = 10000 
MAX_TIMESTAMP_LOOKAHEAD = 14 
NO_BINARY_CHECK = 1 
SHOULD_LINEMERGE = true 
TIME_PREFIX = "startTime": 
TRUNCATE = 0 
pulldown_type=1

but splunk still breaks the event after 257 lines.

best regards
Marco

Tags (1)
0 Karma

kristian_kolb
Ultra Champion

Hi,

Are you applying the settings in the right place? Could be an issue of the config file precedence and/or where in the deployment (forwarder/indexer phases) the configurations is made.

Plaese see;

http://docs.splunk.com/Documentation/Splunk/latest/Admin/Wheretofindtheconfigurationfiles

http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings

Hope this helps,

Kristian

0 Karma

Ayn
Legend

And you do this on the indexer? Or the forwarder?

0 Karma

marcokrueger
Path Finder

Hi Kristian,
I do it in the $SPLUNK_HOME/etc/system/local/props.conf and it seems that this have the highest priority so I wonder why the MAX_EVENTS = 10000 takes no effect.
Is there any condition for MAX_EVENT lets work?

best regards
Marco

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...