We are trying to onboard data from F5 WAF devices to our splunk. F5 team sending it by key value pairs. And one of them is "headers:xxxxxxxxx" (nearly 40 words). When data is getting onboarded and we are checking in splunk web, below the table format headers field is not capturing correctly. It is giving some other value. Same with other field where its value is getting truncated. Please help me in this case.
Start here and see what you can find, otherwise please provide your props.conf configuration if possible so we can actually see what is being attempted vs an example of the actual output. A sample of the log helps when deciphering how your existing props.conf is interacting with the data.