Splunk Enterprise

TCP/UDP truncates files at 10K

tmontney
Builder

Like many questions I've seen here, anything sent via TCP/UDP is being cut off after 10K.

I have a simple app deployed to clients. My inputs.conf has a stanza for a script, and it's to run a program that will (at the end) send JSON data back via TCP. I figured this was better than monitoring an output file. This file is between 40 to 50K. Per suggestions, I created a props.conf in my ./myapp/local.

[tcp://515]
truncate = 100000

Or perhaps I've understood how to implement props.conf correctly. I restarted the Splunk service after making this change, sent the data again, and it's cut off at 10K.

Tags (1)
0 Karma

koshyk
Super Champion

how much increased to? Please note 10K is "bytes" and not characters.
Try putting it as "0" and try

Also I believe if it is json, don't use just bytes, but use something like..

[tcp://515]
 KV_MODE = json
 LINE_BREAKER = "(^){"
 NO_BINARY_CHECK = 1
 TRUNCATE = 0
 SHOULD_LINEMERGE = false
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...