Splunk Search

How to prevent tstats from truncating large fields

rhobby
New Member

I have an accelerated data model with a field with large strings in it.
When I use the spl

| data model dm_name ds_name search | table *

I can see the whole fields.

When I use tstats:

| tstats latest (_time) as _time latest (ds_name. data) as data from datamodel=dm_name.ds_name
where (nodename = ds_name)
groupby ds_name. id prestats=true

the data fields are truncated.

I tried to change [stats] maxvaluesize in limits.conf without success. There seems to be no such config for tstats.

How can I prevent tstats from truncating large fields?

Labels (1)
0 Karma

schplunk_meiste
Engager

"Accelerated fields have a limitation of 1024 bytes per entry, so you cannot use fields that have more than 1024 bytes"

https://dev.splunk.com/enterprise/docs/developapps/manageknowledge/kvstore/usingconfigurationfiles/

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with William Searle

The Splunk Guy: A Developer’s Path from Web to Cloud William is a Splunk Professional Services Consultant with ...

Major Splunk Upgrade – Prepare your Environment for Splunk 10 Now!

Attention App Developers: Test Your Apps with the Splunk 10.0 Beta and Ensure Compatibility Before the ...

Stay Connected: Your Guide to June Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...