- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Truncate logs to 10K for all the sources in SPLUNK (cloud)? Default setting is not applicable for HTTP and TCP l
shilpa155
Observer
03-26-2021
01:02 AM
how to truncate logs to 10K for all the sources in SPLUNK (cloud)? The default setting is not applicable for HTTP and TCP logs. I tried using some regex with sed command but it doesn't work out also there is operator precedence while adding any regex in the prop. conf, so when I add the regex it took that, ignoring the default truncate.
Any help in this
