<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Show Source and save as CSV truncate large events? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Show-Source-and-save-as-CSV-truncate-large-events/m-p/49235#M9364</link>
    <description>&lt;P&gt;Interesting. The main UI displays the full event...&lt;/P&gt;

&lt;P&gt;The solution works, but is of little use to my users, who do not get shell access to the server. I suppose an enhancement is in order.&lt;/P&gt;</description>
    <pubDate>Fri, 17 Sep 2010 21:03:03 GMT</pubDate>
    <dc:creator>pde</dc:creator>
    <dc:date>2010-09-17T21:03:03Z</dc:date>
    <item>
      <title>Show Source and save as CSV truncate large events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Show-Source-and-save-as-CSV-truncate-large-events/m-p/49233#M9362</link>
      <description>&lt;P&gt;I have records that consist of fairly large (200+ lines, &amp;gt; 20 Kb per record) XML documents.&lt;/P&gt;

&lt;P&gt;When I export the results of a search for these records to CSV, the _raw cell is truncated; the full record is not written to the _raw cell (note: not an Excel issue. The records are not larger than the 32K-1 byte Excel maximum, and editing the CSV directly shows that the record is indeed truncated).&lt;/P&gt;

&lt;P&gt;The records are similarly truncated in a "Show Source" view.&lt;/P&gt;

&lt;P&gt;What gives?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;

&lt;P&gt;-Pete&lt;/P&gt;</description>
      <pubDate>Mon, 13 Sep 2010 23:32:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Show-Source-and-save-as-CSV-truncate-large-events/m-p/49233#M9362</guid>
      <dc:creator>pde</dc:creator>
      <dc:date>2010-09-13T23:32:09Z</dc:date>
    </item>
    <item>
      <title>Re: Show Source and save as CSV truncate large events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Show-Source-and-save-as-CSV-truncate-large-events/m-p/49234#M9363</link>
      <description>&lt;P&gt;When the UI typically issues a request for events, it will ask the backend to truncate long events above a certain number of lines.  My guess is that this limit is in force even for show search and export as csv from the UI, because they share a common access point.  To get around this issue, you can append &lt;CODE&gt;"| outputcsv &amp;lt;filename&amp;gt;"&lt;/CODE&gt; to the end of your search, and the full csv file should be written out to &lt;CODE&gt;$SPLUNK_HOME/var/run/splunk/&amp;lt;filename&amp;gt;&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Sep 2010 04:13:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Show-Source-and-save-as-CSV-truncate-large-events/m-p/49234#M9363</guid>
      <dc:creator>steveyz</dc:creator>
      <dc:date>2010-09-17T04:13:30Z</dc:date>
    </item>
    <item>
      <title>Re: Show Source and save as CSV truncate large events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Show-Source-and-save-as-CSV-truncate-large-events/m-p/49235#M9364</link>
      <description>&lt;P&gt;Interesting. The main UI displays the full event...&lt;/P&gt;

&lt;P&gt;The solution works, but is of little use to my users, who do not get shell access to the server. I suppose an enhancement is in order.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Sep 2010 21:03:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Show-Source-and-save-as-CSV-truncate-large-events/m-p/49235#M9364</guid>
      <dc:creator>pde</dc:creator>
      <dc:date>2010-09-17T21:03:03Z</dc:date>
    </item>
  </channel>
</rss>

