I index processed data into Splunk and my client might need to view the raw data file that is used to produce events as well.
Let's say, I am using xml and prepare a comma separated line from the file and index it in Splunk. Is there something that I can set in configuration so that the user sees the raw file that is used to produce the event?
You can display the raw data and the path of the file that generated the event using the following:
[yoursearchhere] | table _raw, source
Is that what you need?