Splunk Search

calculating the truncate value for props.conf ?

Path Finder


How to calculate the truncate value ? is it calculated based on the log size and max_events ? if yes , can anyone please explain me in calculating it ?


0 Karma

Ultra Champion

The TRUNCATE value is in bytes of a single event.

What I tend to do is find the largest event in the logs, and paste it into a decent text editor which reports size.
Then set your truncate value to this + % margin of error.

0 Karma