@manthantsarwade On the limits setting i dont think classic and victoria have much difference, other than the below highlighted ones. #https://help.splunk.com/en/splunk-cloud-platform/administer/admin-manual/10.1.2507/get-started-managing-splunk-cloud-platform/determine-your-splunk-cloud-platform-experience For this scenario, my suggesstion would be Avoid relying on KV_MODE=json for very large payloads. Use spath in searches or detection rules for critical fields. Use field aliases or EVAL in props.conf for the most important fields, so they’re always available without depending on auto‑KV. For detection rules- explicitly call spath to guarantee extraction. Performance - extracting 250+ fields at search time can be expensive. Focus on the subset of fields that detection rules truly need. Regards, Prewin 🌟If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!
... View more