Splunk Search

Splunk not displaying log data

jangid
Builder

My log file contain a long line (35000 chars) with continuous spaces [more then 60 spaces] multiple times inside the log - I can't see this log information in Splunk.

I can't change the log because its coming from 3rd party tool

Any Idea?

Tags (2)
1 Solution

kristian_kolb
Ultra Champion

Have you looked at the TRUNCATE parameter for props.conf?

By default Splunk will cut lines that are longer than 10000 chars. Changing this to 50000 might improve your situation.

Other things to check - if you are not seeing the data at all - are the simple things;

Look for interesting error messages in splunkd.log
Are timestamps parsed correctly? Try to search for 'All Time'
Are you looking in the right index?
Do you have permissions to read that index? Check in the Manager -> Account controls -> roles -> your role

Hope this helps,

Kristian

View solution in original post

jangid
Builder

I can't see log data at all in Splunk.

I think Splunk ignoring data in a line if detect some continuous spaces - I don't know whether its true or not, its just my guess.

0 Karma

Ayn
Legend

Do you not see the line at all in Splunk, or do you see a truncated version of it?

0 Karma

jangid
Builder

one option is I can split this line in multiple line based on the number of spaces.

0 Karma
Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...