Splunk Search

How can I expand/unfold all fields in all events in list view?

nikosattlermhp
Engager

I have many events as the following in my search: alt text

All fields are collapsed at the beginning and I have to unfold every single field by clicking on the little blue "+" (In the screenshot I aleady clicked on the "+".). You can I get all field unfold directly at the beginning so I don't have to click on every "+"?

Thanks in advance.

0 Karma

sanjeev543
Communicator

If you just want to list all the fields getting extracted, then you can use the fieldsummary command

https://docs.splunk.com/Documentation/Splunk/7.3.2/SearchReference/Fieldsummary

Or if the question is to expand the event view please refer below URL

https://answers.splunk.com/answers/559/how-do-you-tweak-splunk-to-display-an-event-that-is-more-than...

0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Deprecation of Splunk Observability Kubernetes “Classic Navigator” UI starting ...

Access to Splunk Observability Kubernetes “Classic Navigator” UI will no longer be available starting January ...

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...