Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Why are search results in Splunk Web getting truncated and not parsed correctly, even though I have TRUNCATE=0 in props.conf?

$
0
0
I am seeing an issue with results being truncated and not parsed correctly for some events when I do a search via Splunk Web. However, if I export the results and look at the event, the entire log is present for the event. TRUNCATE is set to 0 is what I am told. So the whole event is definitely being parsed. Just wondering if there are any UI settings that needs to be changed so it shows the whole message on Splunk Web. The event logged is an exception's stack trace. That is why the log message is so long and we would like to keep the whole message. Would appreciate any help.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>