Reporting

How to show raw data in reports?

Explorer

Hi,

I index processed data into Splunk and my client might need to view the raw data file that is used to produce events as well.
Let's say, I am using xml and prepare a comma separated line from the file and index it in Splunk. Is there something that I can set in configuration so that the user sees the raw file that is used to produce the event?

0 Karma

New Member

It's work to me

0 Karma

New Member

It's work fine to me...

0 Karma

SplunkTrust
SplunkTrust

You can display the raw data and the path of the file that generated the event using the following:

[yoursearchhere] | table _raw, source

Is that what you need?

Thanks,
J

State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!