DOCS-1738 - Document 256KB log message size support - #6881
Conversation
Update max log message size references from 64KB to 256KB across search, collection, and source docs; add a Known limitations section and LogCompare/LogReduce truncation notes; clarify the FER 64KB cap; and add a service release note. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Update the Log Search messages-table limitation to the GA behavior (table shows up to 64KB after expansion; full message via Log Message Inspector), and drop the unverified large-log source examples from the release note. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
Holding off on approval — the PR description lists three open items still unconfirmed:
Could you confirm these and check the boxes before this goes up for merge? The doc mechanics (links, cross-references, consistency of the 64KB→256KB updates across all affected files) all check out — just want the factual claims nailed down first. |
Adds known-limitation notes for Slack's message truncation and Jira Cloud's 32,767-character issue description limit, called out directly on each webhook connection page and cross-linked from the central 256KB known limitations list, since larger messages make both limits more likely to be hit.
Adds Slack's 40,000-character hard limit, splits the search-large- messages known limitations into Sumo Logic platform vs. downstream webhook connection limitations for clarity, previews both in the intro, and tightens the release note with the same distinction.
lei-sumo
left a comment
There was a problem hiding this comment.
during GNG meeting, we made another pass and left several comments.
…elease note - Correct the Log Search messages table limit from 64KB to the GA value of 25,000 characters, and note that JSON values in larger messages aren't rendered as JSON fields by default (per ssharma-sumo). - Correct Jira Cloud webhook behavior: oversized descriptions are truncated with "..." and the issue is still created, not a 400 Bad Request failure (per lei-sumo). - Drop the release note's summarized limitations bullets, which mischaracterized the Field Extraction Rule limit as a message-size cap rather than a cumulative-field-size cap (per kevin-sumo/lei-sumo), and link to the doc's Known limitations section instead.
kimsauce
left a comment
There was a problem hiding this comment.
Fast content-accuracy pass on this doc PR. Nothing blocking, but flagging a few unsourced/unconfirmed technical claims worth a second look before merge (see inline comments). Also noting the PR description itself still has 3 unchecked "confirm before ready" items (FER limit, Cloud SIEM wording, release note date).
Confirmed with Chetan Meena in Slack: rollout runs August 18-26, 2026.
amee-sumo
left a comment
There was a problem hiding this comment.
Approving — the doc mechanics are solid: all 64KB→256KB / 65536→262144 conversions check out, cross-links between search-large-messages.md, logcompare.md, detect-patterns-with-logreduce.md, slack.md, and jira-cloud.md are correct and reciprocal, and most of the factual-accuracy concerns raised earlier in this thread (25,000-char table limit, LogCompare/LogReduce truncation, cloud syslog/multiline/Qualys C2C) have real confirmations behind them now.
One blocking item before merge: the PR description's own checklist still has "Cloud SIEM limitation wording" unchecked. The "Parsing and mapping might not process messages larger than 64KB correctly" claim in search-large-messages.md's Known Limitations section is sourced from the DOCS-1738 ticket text, but per @JV0812's Aug 19 comment it's still pending a final nod from the SIEM team (ref SUMO-257908) — please get that confirmation and check the box before merging.
Non-blocking paperwork nits: the PR description still references the old release-note filename (2026-07-09-search.md, renamed to 2026-08-19-search.md), and doesn't mention the Slack/Jira Cloud webhook char-limit work (DOCS-1773) that's bundled into this branch — worth updating for a complete paper trail.
|
Thanks @amee-sumo! Fixed both non-blocking items in the PR description:
The blocking item (Cloud SIEM wording, ref SUMO-257908) is still open — still waiting on that final confirmation from the SIEM team before checking the box. |
|
@amee-sumo Confirmation received on the blocking item — checked the box. SUMO-257908 is closed as "Not a Bug — work by design." More importantly, the umbrella epic for this 256KB GA (SUMO-282954) explicitly states: "CSIEM product will NOT be part of the initial GA but will be addressed as a follow up effort." So Cloud SIEM staying capped at 64KB is deliberate, not a pending fix — and the doc line itself doesn't make any claim about 256KB, it just states the existing 64KB parsing/mapping limitation, which remains accurate as written. All three "Open items to confirm" are now checked off. Should be ready to merge. |
Purpose of this pull request
This pull request documents the increase of the maximum log message size from 64KB to 256KB, calls out the known limitations, and adds a service release note. It also bundles DOCS-1773 (Slack and Jira Cloud webhook character-limit documentation).
Changes:
_sizetruncation from 65536 to 262144) insearch-large-messages.md,collect-multiline-logs.md,cloud-syslog-source/index.md, andqualys-vmdr-source.md.search-large-messages.md(LogCompare/LogReduce, UI 25-messages-per-page, Cloud SIEM, FER).logcompare.mdanddetect-patterns-with-logreduce.md.fer-limitations.mdthat the 64KB cumulative field cap applies regardless of message size.slack.md(40,000-character Slack message limit) andjira-cloud.md(32,767-character Jira Cloud issue description limit) — DOCS-1773.blog-service/2026-08-19-search.md(renamed from2026-07-09-search.mdto match actual publish date).Open items to confirm before marking ready
Select the type of change
Ticket (if applicable)
https://sumologic.atlassian.net/browse/DOCS-1738 (epic: SUMO-288529)
Also bundles: https://sumologic.atlassian.net/browse/DOCS-1773