Splunk Dev

How to handle truncation error in Splunk SDK?

waghpra
New Member

Hi Pals,

Thank you for viewing my question.

I am retrieving my data through C# and Splunk SDK. But while extracting the results, I am facing the below truncation issue:
"Command mvexpand output will be truncated at XXXXX results due to excessive memory usage.......... max_mem_usage_mb has been reached".
I have added all the required filter before MVEXPAND but then too no luck, So below is my question:
1. Currently, I am slicing the timestamp to minutes and extracting the results. But is there any finer way which Splunk recommend?
2. Can the output of Splunk SDK be JSON? If yes, then doing so can have better results?

Labels (1)
0 Karma

to4kawa
Ultra Champion
0 Karma

pbankar
Path Finder

@waghpra, you may check your /default/props.conf in your app.
Check - https://answers.splunk.com/answers/41648/linebreakingprocessor-truncating-line-because-limit-of-1000...

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...