Knowledge Management

How to increaser raw log view limitation when using field extraction via the UI?

DanAlexander
Communicator

Hello network,

I need help understanding how to increase the number of lines within the UI Field Extraction

For example, I have an event containing 38 lines and when sampling for applying regex while field extracting, it gives me visibility of 20 lines only, which prevents me of seen what I actually want to extract as a field.

I did check the ui-prefs.conf but not entirely sure if this is the right place to expand and maximize the window/workflow so I can see all lines and work with these.

SPLUNK.jpg

Thank you  

Labels (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

this is not exactly what you are asking, but I prefer to use https://regex101.com for creating field extractions. Another what you maybe could use is erex command?

r. Ismo

0 Karma

DanAlexander
Communicator

Hi,

Thanks for the reply @isoutamo 

We are using these but wanted to see if I can change the limitations within the UI

regards,

Dan

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...