Splunk Search

HEC large field value not extracted but is in _raw

simpkins1958
Contributor

Have a field in our HEC input that is larger the 10,000 characters. When searching the data input from HEC the field is has not been extracted. It is in _raw and I can pull it out of there. Really would like to be able to have the field extracted.

props.conf has:
TRUNCATE = 0

I can manually input the same data via a text file and the large field (a blob of JSON text) is extracted and available fine. Just not when input via HEC.

See screen shotsalt text

0 Karma
1 Solution

starcher
Influencer

If sending into HEC using the event not raw endpoint in JSON.
Set KV_MODE = JSON on the props for that sourcetype. NOT auto...
http://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf?splunkbot

View solution in original post

0 Karma

starcher
Influencer

If sending into HEC using the event not raw endpoint in JSON.
Set KV_MODE = JSON on the props for that sourcetype. NOT auto...
http://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf?splunkbot

0 Karma

simpkins1958
Contributor

Adding this to props.conf fixed the issue:

[nm_MobileDiagnosticsReportData]
KV_MODE = json

0 Karma

sdchakraborty
Contributor

Hi,

Canyou increase the maxchars in limits.conf and try.

https://docs.splunk.com/Documentation/Splunk/7.2.4/Admin/Limitsconf

Sid

0 Karma

simpkins1958
Contributor

When the events are inserted via HEC running a fieldsummary DOES NOT show report field. When the same raw event is input via a file fieldsummary DOES show report field.

0 Karma

maciep
Champion

i'll ask the dumb question...is the report field in the "3 more fields" link?

0 Karma

simpkins1958
Contributor

No the report field is not listed.

0 Karma
Get Updates on the Splunk Community!

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...

Developer Spotlight with Guilhem Marchand

From Splunk Engineer to Founder: The Journey Behind TrackMe    After spending over 12 years working full time ...