Security

Disable or increase truncation of hostnames and timestamp

Communicator

Hello,

we have longer hostnames. Like "gateway_chvj500ld800.mycompany.net".

Its truncated to something like "gateway_chvj.....mycompany.net" So the important part is missing.

Same with Timestamps.

How can we eliminate the truncation?

Cheers,

Jens

Tags (1)
0 Karma

Communicator
0 Karma

Splunk Employee
Splunk Employee

I don't believe there is an easy way to do it, but I might be wrong. I would create a rex and replace for your hostnames when running reports, similar to what is in this Question:

http://answers.splunk.com/questions/7077/how-can-i-rename-the-host-names-for-my-chart

0 Karma

Splunk Employee
Splunk Employee

im sure it is in the UI, on the field picker little blue box.
JensT, if you mouse over one of the hosts, or timestamps, you should notice that the timestamp/host is fully there. If you click on one, it will add it correctly to the search query. The truncation is due to the available screen-space as mick points out, and im not sure if there can be done anything against it. I spoke to a UI a while back and seems that is the way it's supposed to be. JV might want to comment on this, if he sees this thread.

Splunk Employee
Splunk Employee

Are you talking about the actual field being truncated or is it just the way it is displayed in the UI, due to the available screen-space? Any chance to a screenshot?

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!