Blog tagged as Event Truncation Issues

Event Truncation Issues - Splunk Troubleshooting Use Case - 11
Issue-5: 
Json Data - Events are truncated, only half of the event is indexed
Root Cause:
Event size is too big - more than 10,000 bytes
Solution:
Configure “TRUNCATE” property in the sourcetype, as shown below in props.conf
[yoursourcetype]
TRUNCATE = 99999

13.06.24 10:53 PM - Comment(s)