Splunk
SPLK-3003 · Question #45
A customer is having issues with truncated events greater than 64K. What configuration should be deployed to a universal forwarder (UF) to fix the issue?
The correct answer is C. EVENT_BREAKER_ENABLE and EVENT_BREAKER regular expression settings per sourcetype. https://docs.splunk.com/Documentation/Splunk/8.1.0/Data/Resolvedataqualityissues
Data Ingestion and Configuration
Question
A customer is having issues with truncated events greater than 64K. What configuration should be deployed to a universal forwarder (UF) to fix the issue?
Options
- ANone. Splunk default configurations will process the events as needed; the UF is not causing
- BConfigure the best practice magic 6 or great 8 props.conf settings.
- CEVENT_BREAKER_ENABLE and EVENT_BREAKER regular expression settings per sourcetype.
- DGlobal EVENT_BREAKER_ENABLE and EVENT_BREAKER regular expression settings.
How the community answered
(66 responses)- A11% (7)
- B3% (2)
- C79% (52)
- D8% (5)
Explanation
https://docs.splunk.com/Documentation/Splunk/8.1.0/Data/Resolvedataqualityissues
Topics
#EVENT_BREAKER#event truncation#universal forwarder#props.conf
Community Discussion
No community discussion yet for this question.