Getting Data In

Why am I getting the following error from the LineBreakingProcessor: "Truncating line because limit of 10000 bytes has been exceeded?"

swaroopbr
Engager

Hi Team,

I am using Splunk 7.1.1 and i have been getting this error constantly

LineBreakingProcessor - Truncating line because limit of 10000 bytes has been exceeded

As per various Splunk answers, I tried TRUNCATE=0 & TRUNCATE=999999 as well, but none of them worked for me. I had made sure the setting are in the correct props.conf

Any suggestions how do i get rid of this error?

0 Karma

scheng_splunk
Splunk Employee
Splunk Employee

LineBreaking is done as part of parsing pipeline:
http://docs.splunk.com/Documentation/Splunk/7.2.1/Indexer/Howindexingworks#Event_processing_and_the_...

More details about event processing pipelines:
https://wiki.splunk.com/Community:HowIndexingWorks

Please note sometime parsing can be done by the Heavy Forwarder:
http://docs.splunk.com/Documentation/Splunk/7.2.1/Deploy/Componentsofadistributedenvironment#How_com...

If by any chance you have HF doing the parsing, perhaps you should apply relevant props.conf on the Heavy Forwarder.

You may check splunkd.log on relevant Splunk components searching for "truncating" and look for if the particular log is getting truncated due to any setting.

0 Karma

prakash007
Builder

Make sure you have this configs on your indexers...
http://docs.splunk.com/Documentation/Splunk/7.2.1/Admin/Propsconf#Line_breaking

0 Karma

dkeck
Influencer

Did you restart splunkd after changing the props?
Maybe check spelling ?
Please post your conf

0 Karma
Get Updates on the Splunk Community!

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Splunk Education Goes to Washington | Splunk GovSummit 2024

If you’re in the Washington, D.C. area, this is your opportunity to take your career and Splunk skills to the ...