Getting Data In

How to show source through splunk api

beibeiqi0916
New Member

Now returned result from _raw field is shown limited lines. Is there a way I can get source through API, just like from Splunk UI, we can choose show source from event action.
I have already tried to add -d max_lines=500, but looks like still not working for me.
Thank you so much

Tags (2)
0 Karma
Get Updates on the Splunk Community!

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...