Splunk Search

HEC large field value not extracted but is in _raw

simpkins1958
Contributor

Have a field in our HEC input that is larger the 10,000 characters. When searching the data input from HEC the field is has not been extracted. It is in _raw and I can pull it out of there. Really would like to be able to have the field extracted.

props.conf has:
TRUNCATE = 0

I can manually input the same data via a text file and the large field (a blob of JSON text) is extracted and available fine. Just not when input via HEC.

See screen shotsalt text

0 Karma
1 Solution

starcher
SplunkTrust
SplunkTrust

If sending into HEC using the event not raw endpoint in JSON.
Set KV_MODE = JSON on the props for that sourcetype. NOT auto...
http://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf?splunkbot

View solution in original post

0 Karma

starcher
SplunkTrust
SplunkTrust

If sending into HEC using the event not raw endpoint in JSON.
Set KV_MODE = JSON on the props for that sourcetype. NOT auto...
http://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf?splunkbot

0 Karma

simpkins1958
Contributor

Adding this to props.conf fixed the issue:

[nm_MobileDiagnosticsReportData]
KV_MODE = json

0 Karma

sdchakraborty
Contributor

Hi,

Canyou increase the maxchars in limits.conf and try.

https://docs.splunk.com/Documentation/Splunk/7.2.4/Admin/Limitsconf

Sid

0 Karma

simpkins1958
Contributor

When the events are inserted via HEC running a fieldsummary DOES NOT show report field. When the same raw event is input via a file fieldsummary DOES show report field.

0 Karma

maciep
Champion

i'll ask the dumb question...is the report field in the "3 more fields" link?

0 Karma

simpkins1958
Contributor

No the report field is not listed.

0 Karma
Get Updates on the Splunk Community!

Observability | How to Think About Instrumentation Overhead (White Paper)

Novice observability practitioners are often overly obsessed with performance. They might approach ...

Cloud Platform | Get Resiliency in the Cloud Event (Register Now!)

IDC Report: Enterprises Gain Higher Efficiency and Resiliency With Migration to Cloud  Today many enterprises ...

The Great Resilience Quest: 10th Leaderboard Update

The tenth leaderboard update (11.23-12.05) for The Great Resilience Quest is out >> As our brave ...