Getting Data In

_raw doesn't have the full event data that I see by clicking the menu EventActions->ShowSource on each search result

splunkering
Explorer

I have a jmx sourcetype that has several 100s of lines of metrics. When these are ingested into splunk, I see only a few lines from these events in the _raw and nothing of use to me in any other fields
I see the full 400 odd lines when I click on EventActions->ShowSource on each event. These "hidden" lines are the ones that I am most interested in but they are not searchable in splunk.

What is the reason for this not being a part of _raw? How can I fix this please?

Thanks

Tags (1)
0 Karma

FrankVl
Ultra Champion

What are your inputs.conf and props.conf settings for this data? I'm guessing the data either get's truncated, or split into separate events (part of which are out of sight because of lack of proper timestamping or so perhaps)?

Can you share a (partial) sample of what the data looks like and a screenshot of how it shows up in Splunk?

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...