Splunk Search

How to display the complete source without ...

jackiewkc
Path Finder

The results of my queries in Splunk are truncated ie, it only shows:

source =/data/logs/sdf/sdfdsfds/f/sdf/dsf/dsf/dsf/dsf/d/fsd/fd/sf/sdf/sd/fsd/f/sdf/sd/fs/dfggd/f…

when I instead want to see the full log name

source =/data/logs/sdf/sdfdsfds/f/sdf/dsf/dsf/dsf/dsf/d/fsd/fd/sf/sdf/sd/fsd/f/sdf/sd/fs/dfggd/fsd/fs/ftest.log

Can it be configured in Splunk to expand the source field to show the full field value by default?

FYI it seems like the source field has a max length of 90 characters including the 3 dots.

Thanks in advance.

Jackie

Tags (2)
0 Karma
1 Solution

woodcock
Esteemed Legend

You have not told us where you are seeing your data.
1: Is it on the events tab as a selected field?
2: Is it on the statistics tab as a value in a column?
3: Is it on the visualization tab; if so, what visualization are you using?

I will assume the problem is #1 and the solution is to add this to move to #2 which should not have this problem:

... | table *

If you ask questions better, you will get better answers.

View solution in original post

0 Karma

woodcock
Esteemed Legend

You have not told us where you are seeing your data.
1: Is it on the events tab as a selected field?
2: Is it on the statistics tab as a value in a column?
3: Is it on the visualization tab; if so, what visualization are you using?

I will assume the problem is #1 and the solution is to add this to move to #2 which should not have this problem:

... | table *

If you ask questions better, you will get better answers.

0 Karma

jackiewkc
Path Finder

Thanks for the reply. And yes, I was talking about the event tab. And the scenario is that when I do a simple search like "index=abc". you can see the events in the events tab with ... as part of the source when it is longer than 90 characters. I wanted to know if it is possible to configure Splunk to simply show the complete values of the soruce field in the normal search result without doing anything like table * to alter how the results are displayed.
Based on your reply, I take it the answer is no. If this is not the case and in fact there is a way to do it, please do let me know.
Thanks.

0 Karma

woodcock
Esteemed Legend

I am unaware of any way to control this, but that is not to say it is impossible. I would raise a support case with Splunk and ask them to add this as a feature and they will tell you if there is some arcane setting somewhere (unlikely).

0 Karma
Get Updates on the Splunk Community!

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Index This | What goes away as soon as you talk about it?

May 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

What's New in Splunk Observability Cloud and Splunk AppDynamics - May 2025

This month, we’re delivering several new innovations in Splunk Observability Cloud and Splunk AppDynamics ...