Reporting

How to show raw data in reports?

sdaruna
Explorer

Hi,

I index processed data into Splunk and my client might need to view the raw data file that is used to produce events as well.
Let's say, I am using xml and prepare a comma separated line from the file and index it in Splunk. Is there something that I can set in configuration so that the user sees the raw file that is used to produce the event?

0 Karma

spitinfra
New Member

It's work to me

0 Karma

spitinfra
New Member

It's work fine to me...

0 Karma

javiergn
Super Champion

You can display the raw data and the path of the file that generated the event using the following:

[yoursearchhere] | table _raw, source

Is that what you need?

Thanks,
J

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...