Hi Team,
I am using Splunk 7.1.1 and i have been getting this error constantly
LineBreakingProcessor - Truncating line because limit of 10000 bytes has been exceeded
As per various Splunk answers, I tried TRUNCATE=0 & TRUNCATE=999999 as well, but none of them worked for me. I had made sure the setting are in the correct props.conf
Any suggestions how do i get rid of this error?
LineBreaking is done as part of parsing pipeline:
http://docs.splunk.com/Documentation/Splunk/7.2.1/Indexer/Howindexingworks#Event_processing_and_the_...
More details about event processing pipelines:
https://wiki.splunk.com/Community:HowIndexingWorks
Please note sometime parsing can be done by the Heavy Forwarder:
http://docs.splunk.com/Documentation/Splunk/7.2.1/Deploy/Componentsofadistributedenvironment#How_com...
If by any chance you have HF doing the parsing, perhaps you should apply relevant props.conf on the Heavy Forwarder.
You may check splunkd.log on relevant Splunk components searching for "truncating" and look for if the particular log is getting truncated due to any setting.
Make sure you have this configs on your indexers...
http://docs.splunk.com/Documentation/Splunk/7.2.1/Admin/Propsconf#Line_breaking
Did you restart splunkd after changing the props?
Maybe check spelling ?
Please post your conf