Splunk Search

How to show more than 50 events on a page in 7.x ?

zebu14
Explorer

Hello,
In Splunk previous versions (5.x) there was an editable file to be able to add more choices for the number of displayed events (10/20/50 per page)

I want to display more events on each page (100 / 200) because my logs are quite verbose.

The question has already been asked for Splunk 6.x, but I am searching for a solution on version 7.1.

Any idea ?

Thank you

Tags (2)

aguthrie1190
Path Finder

I'm not sure how supported this change is. But you can change the values in these two files:
/opt/splunk/share/splunk/search_mrsparkle/exposed/build/pages/enterprise/search.js
/opt/splunk/share/splunk/search_mrsparkle/exposed/build/pages/enterprise/common.js

Look for this JSON block:
{value:"10",label:("10 per page").t()},{value:"20",label:("20 per page").t()},{value:"50",label:_("50 per page").t()}

And add additional values to it:
{value:"10",label:("10 per page").t()},{value:"20",label:("20 per page").t()},{value:"50",label:("50 per page").t()},{value:"100",label:("100 per page").t()}

This code appears multiple times in each file, so you'll have to replace it each time.

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi, this you want on the splunk search page or on the dashboard?

0 Karma

zebu14
Explorer

On the splunk search page, yes.

I tried to edit the following files :
./share/splunk/search_mrsparkle/exposed/js/views/search/results/eventspane/controls/Master.js
./share/splunk/search_mrsparkle/exposed/js/views/search/searchhistory/historycontent/Master.js
./share/splunk/search_mrsparkle/exposed/js/views/dataset/tablecontainer/results/DatasetControls.js

With no success for the moment.

0 Karma

inventsekar
SplunkTrust
SplunkTrust
0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...