Splunk Cloud Platform

Issue with large file size not getting read in Splunk

paragg
Loves-to-Learn Lots

For a particular sourcetype I am facing log ingestion issue. Getting below error. 
As checked with the team, this log file can not be split. So is there any solution to resolve this issue.

paragg_0-1739218887388.png

 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

That's a warning, not an error.  The file will be ingested, but while Splunk is busy with it other monitored files are ignored.

Consider standing up a separate UF on that server just for the large files.

Also, make sure maxKBps in limits.conf is set to 0 or the largest value the network can support.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...