Splunk Search

TRUCANTE Logs

andgarciaa
Explorer

Hello,

I am using Splunk Cloud, for some our sourcetypes we have defined specific TRUNCATE values. I have a couple of questions.

If `TRUNCATE` value is not defined for a sourcetype, what is the default limit of chars?

Is there any guideline document or rules on how to define TRUNCATE? Especially if it is recommended to set something higher than 50k or 80k chars as a limit.

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @andgarciaa ,

you can find more infos at https://docs.splunk.com/Documentation/Splunk/9.2.1/Admin/Propsconf

and answering to your question:

TRUNCATE = <non-negative integer>
* The default maximum line length, in bytes.
* Although this is in bytes, line length is rounded down when this would
  otherwise land mid-character for multi-byte characters.
* Set to 0 if you never want truncation (very long lines are, however, often
  a sign of garbage data).
* Default: 10000

There isn't a general guideline: usually the TRUNCATE value is defined by the specific Add-On you're using and it's related to the technology you're using.

If you are ingesting a custom log, you have to choose the correct one by yourself.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @andgarciaa ,

you can find more infos at https://docs.splunk.com/Documentation/Splunk/9.2.1/Admin/Propsconf

and answering to your question:

TRUNCATE = <non-negative integer>
* The default maximum line length, in bytes.
* Although this is in bytes, line length is rounded down when this would
  otherwise land mid-character for multi-byte characters.
* Set to 0 if you never want truncation (very long lines are, however, often
  a sign of garbage data).
* Default: 10000

There isn't a general guideline: usually the TRUNCATE value is defined by the specific Add-On you're using and it's related to the technology you're using.

If you are ingesting a custom log, you have to choose the correct one by yourself.

Ciao.

Giuseppe

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...