We are facing issue while parsing the lengthy Json file. Splunk is picking up incomplete data. Attaching the specifications of source type used, any help would be appreciated. Thanks!!
What happened with that setting? Without specifics, it's hard to tell.
Hi @to4kawa ,
The given source type(provided in the screenshot) was parsing the long JSON input correctly till few days back. But after migrating from Splunk version 7.3.4 to 8.0.5, the full JSON data is not getting picked up by Splunk.
Is there some attribute present in configuration files of Splunk which defines the length of an event ? If yes, we can try increasing its value so that we get complete data and it gets correctly parsed by the given sourcetype?
