Getting Data In

_raw doesn't have the full event data that I see by clicking the menu EventActions->ShowSource on each search result

splunkering
Explorer

I have a jmx sourcetype that has several 100s of lines of metrics. When these are ingested into splunk, I see only a few lines from these events in the _raw and nothing of use to me in any other fields
I see the full 400 odd lines when I click on EventActions->ShowSource on each event. These "hidden" lines are the ones that I am most interested in but they are not searchable in splunk.

What is the reason for this not being a part of _raw? How can I fix this please?

Thanks

Tags (1)
0 Karma

FrankVl
Ultra Champion

What are your inputs.conf and props.conf settings for this data? I'm guessing the data either get's truncated, or split into separate events (part of which are out of sight because of lack of proper timestamping or so perhaps)?

Can you share a (partial) sample of what the data looks like and a screenshot of how it shows up in Splunk?

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...