- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Splunk query results are getting truncated when i am creating a table
Splunk-Star
Loves-to-Learn Lots
02-15-2024
07:00 AM
my splunk query results are getting truncated when creating a table Is there any workaround to avoid this ??
index=gbi_* (AppName=*) | table SQL
Labels (7)
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Splunk-Star
Loves-to-Learn Lots
03-12-2024
10:52 PM
applied rex, after that it worked. Thanks
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
PickleRick

SplunkTrust
02-16-2024
11:14 AM
Main question is whether your data is getting truncated when you're displaying it (which is kinda unlikely) or has it been truncated on ingestion. Check your data with this:
index=gbi_* (AppName=*)
| eval strlen=len(_raw)
| stats max(strlen)
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ITWhisperer

SplunkTrust
02-15-2024
07:12 AM
Does the answer to this similar question help?
