Splunk Search

How can I expand/unfold all fields in all events in list view?

nikosattlermhp
Engager

I have many events as the following in my search: alt text

All fields are collapsed at the beginning and I have to unfold every single field by clicking on the little blue "+" (In the screenshot I aleady clicked on the "+".). You can I get all field unfold directly at the beginning so I don't have to click on every "+"?

Thanks in advance.

0 Karma

sanjeev543
Communicator

If you just want to list all the fields getting extracted, then you can use the fieldsummary command

https://docs.splunk.com/Documentation/Splunk/7.3.2/SearchReference/Fieldsummary

Or if the question is to expand the event view please refer below URL

https://answers.splunk.com/answers/559/how-do-you-tweak-splunk-to-display-an-event-that-is-more-than...

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...