how to truncate logs to 10K for all the sources in SPLUNK (cloud)? The default setting is not applicable for HTTP and TCP logs. I tried using some regex with sed command but it doesn't work out also there is operator precedence while adding any regex in the prop. conf, so when I add the regex it took that, ignoring the default truncate.
Any help in this