Splunk Search

Splunk not displaying log data

jangid
Builder

My log file contain a long line (35000 chars) with continuous spaces [more then 60 spaces] multiple times inside the log - I can't see this log information in Splunk.

I can't change the log because its coming from 3rd party tool

Any Idea?

Tags (2)
1 Solution

kristian_kolb
Ultra Champion

Have you looked at the TRUNCATE parameter for props.conf?

By default Splunk will cut lines that are longer than 10000 chars. Changing this to 50000 might improve your situation.

Other things to check - if you are not seeing the data at all - are the simple things;

Look for interesting error messages in splunkd.log
Are timestamps parsed correctly? Try to search for 'All Time'
Are you looking in the right index?
Do you have permissions to read that index? Check in the Manager -> Account controls -> roles -> your role

Hope this helps,

Kristian

View solution in original post

jangid
Builder

I can't see log data at all in Splunk.

I think Splunk ignoring data in a line if detect some continuous spaces - I don't know whether its true or not, its just my guess.

0 Karma

Ayn
Legend

Do you not see the line at all in Splunk, or do you see a truncated version of it?

0 Karma

jangid
Builder

one option is I can split this line in multiple line based on the number of spaces.

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...