Security

Disable or increase truncation of hostnames and timestamp

JensT
Communicator

Hello,

we have longer hostnames. Like "gateway_chvj500ld800.mycompany.net".

Its truncated to something like "gateway_chvj.....mycompany.net" So the important part is missing.

Same with Timestamps.

How can we eliminate the truncation?

Cheers,

Jens

Tags (1)
0 Karma

JensT
Communicator
0 Karma

Simeon
Splunk Employee
Splunk Employee

I don't believe there is an easy way to do it, but I might be wrong. I would create a rex and replace for your hostnames when running reports, similar to what is in this Question:

http://answers.splunk.com/questions/7077/how-can-i-rename-the-host-names-for-my-chart

0 Karma

Genti
Splunk Employee
Splunk Employee

im sure it is in the UI, on the field picker little blue box.
JensT, if you mouse over one of the hosts, or timestamps, you should notice that the timestamp/host is fully there. If you click on one, it will add it correctly to the search query. The truncation is due to the available screen-space as mick points out, and im not sure if there can be done anything against it. I spoke to a UI a while back and seems that is the way it's supposed to be. JV might want to comment on this, if he sees this thread.

Mick
Splunk Employee
Splunk Employee

Are you talking about the actual field being truncated or is it just the way it is displayed in the UI, due to the available screen-space? Any chance to a screenshot?

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...