Splunk Search

Has anyone come across this warning below in Splunk Web?

mohdmikhael
Explorer

Hi,

I recently came across this warning on Splunk web and was just wondering if anyone else has encountered this before and how to go about solving it?

The warning is as follows:
"Events are not displayed in the search results because _raw fields exceed the limit of 16777216 characters. Ensure that _raw fields are below the given character limit or switch to the CSV serialization format by setting 'results_serial_format=csv' in limits.conf. Switching to the CSV serialization....."

Any input is greatly appreciated and thank you in advance.

Mikhael

Labels (2)
Tags (3)
0 Karma

kanggao
New Member
do you figure out the root cause? it also displayed in our Splunk UI.
0 Karma

rahulg
Explorer

Did you find any solution for this, i also see this error on UI

0 Karma

PaulPanther
Motivator

@mohdmikhael For me it looks like that the affected event(s) are not splitted correctly. 

Have you already verified what kind of data ist affected?

Regarding event breaking in Splunk: Configure event line breaking - Splunk Documentation

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...