Does it show the raw data Splunk indexed for this specific event? or the entire sources?
In my search, when I click "show source" under "event actions", it seems to only show a fraction of the raw data and I am not sure what is the time period of it.
It gives you surrounding events of the selected event from that source and host.
I found this helpful.
https://answers.splunk.com/answers/72721/no-of-events-in-show-source-view.html
It gives you surrounding events of the selected event from that source and host.
I found this helpful.
https://answers.splunk.com/answers/72721/no-of-events-in-show-source-view.html
Thank you for your help!