Splunk Search

Has anyone come across this warning below in Splunk Web?

mohdmikhael
Explorer

Hi,

I recently came across this warning on Splunk web and was just wondering if anyone else has encountered this before and how to go about solving it?

The warning is as follows:
"Events are not displayed in the search results because _raw fields exceed the limit of 16777216 characters. Ensure that _raw fields are below the given character limit or switch to the CSV serialization format by setting 'results_serial_format=csv' in limits.conf. Switching to the CSV serialization....."

Any input is greatly appreciated and thank you in advance.

Mikhael

Labels (2)
Tags (3)
0 Karma

kanggao
New Member
do you figure out the root cause? it also displayed in our Splunk UI.
0 Karma

rahulg
Explorer

Did you find any solution for this, i also see this error on UI

0 Karma

PaulPanther
Motivator

@mohdmikhael For me it looks like that the affected event(s) are not splitted correctly. 

Have you already verified what kind of data ist affected?

Regarding event breaking in Splunk: Configure event line breaking - Splunk Documentation

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...