<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to display the complete source without ... in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-display-the-complete-source-without/m-p/189529#M54598</link>
    <description>&lt;P&gt;You have not told us &lt;EM&gt;where&lt;/EM&gt; you are seeing your data.&lt;BR /&gt;
1: Is it on the events tab as a selected field? &lt;BR /&gt;
2: Is it on the statistics tab as a value in a column? &lt;BR /&gt;
3: Is it on the visualization tab; if so, what visualization are you using? &lt;/P&gt;

&lt;P&gt;I will assume the problem is #1 and the solution is to add this to move to #2 which should not have this problem:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | table *
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If you ask questions better, you will get better answers.&lt;/P&gt;</description>
    <pubDate>Fri, 03 Jul 2015 01:25:01 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2015-07-03T01:25:01Z</dc:date>
    <item>
      <title>How to display the complete source without ...</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-display-the-complete-source-without/m-p/189528#M54597</link>
      <description>&lt;P&gt;The results of my queries in Splunk are truncated ie, it only shows:&lt;/P&gt;

&lt;P&gt;source =/data/logs/sdf/sdfdsfds/f/sdf/dsf/dsf/dsf/dsf/d/fsd/fd/sf/sdf/sd/fsd/f/sdf/sd/fs/dfggd/f…&lt;/P&gt;

&lt;P&gt;when I instead want to see the full log name&lt;/P&gt;

&lt;P&gt;source =/data/logs/sdf/sdfdsfds/f/sdf/dsf/dsf/dsf/dsf/d/fsd/fd/sf/sdf/sd/fsd/f/sdf/sd/fs/dfggd/fsd/fs/ftest.log&lt;/P&gt;

&lt;P&gt;Can it be configured in Splunk to expand the source field to show the full field value by default?&lt;/P&gt;

&lt;P&gt;FYI it seems like the source field has a max length of 90 characters including the 3 dots.&lt;/P&gt;

&lt;P&gt;Thanks in advance.&lt;/P&gt;

&lt;P&gt;Jackie&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2015 15:52:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-display-the-complete-source-without/m-p/189528#M54597</guid>
      <dc:creator>jackiewkc</dc:creator>
      <dc:date>2015-07-02T15:52:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to display the complete source without ...</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-display-the-complete-source-without/m-p/189529#M54598</link>
      <description>&lt;P&gt;You have not told us &lt;EM&gt;where&lt;/EM&gt; you are seeing your data.&lt;BR /&gt;
1: Is it on the events tab as a selected field? &lt;BR /&gt;
2: Is it on the statistics tab as a value in a column? &lt;BR /&gt;
3: Is it on the visualization tab; if so, what visualization are you using? &lt;/P&gt;

&lt;P&gt;I will assume the problem is #1 and the solution is to add this to move to #2 which should not have this problem:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | table *
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If you ask questions better, you will get better answers.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jul 2015 01:25:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-display-the-complete-source-without/m-p/189529#M54598</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-07-03T01:25:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to display the complete source without ...</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-display-the-complete-source-without/m-p/189530#M54599</link>
      <description>&lt;P&gt;Thanks for the reply. And yes, I was talking about the event tab. And the scenario is that when I do a simple search like "index=abc". you can see the events in the events tab with ... as part of the source when it is longer than 90 characters. I wanted to know if it is possible to configure Splunk to simply show the complete values of the soruce field in the normal search result without doing anything like table * to alter how the results are displayed.&lt;BR /&gt;
Based on your reply, I take it the answer is no. If this is not the case and in fact there is a way to do it, please do let me know.&lt;BR /&gt;
Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jul 2015 10:25:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-display-the-complete-source-without/m-p/189530#M54599</guid>
      <dc:creator>jackiewkc</dc:creator>
      <dc:date>2015-07-03T10:25:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to display the complete source without ...</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-display-the-complete-source-without/m-p/189531#M54600</link>
      <description>&lt;P&gt;I am unaware of any way to control this, but that is not to say it is impossible.  I would raise a support case with Splunk and ask them to add this as a feature and they will tell you if there is some arcane setting somewhere (unlikely).&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jul 2015 13:48:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-display-the-complete-source-without/m-p/189531#M54600</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-07-03T13:48:20Z</dc:date>
    </item>
  </channel>
</rss>

