Splunk Search

How to limit column size in top reports

MattG
New Member

Here is my query:
source="WinEventLog:Application" OR source="WinEventLog:System" |top limit=10 Type,EventCode, SourceName, Message

The message field is long, consequently I cannot see the counts without scrolling. Is there a way to limit the Message fields displayed length? It would be ideal if this could be like HTML where you provide a % instead a hard char limit

Tags (2)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

If you know how long you want it to show you can append this to your search:

... | fieldformat Message=if(length(Message) > 150, substr(Message, 0, 150) + "...", Message)

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

If you know how long you want it to show you can append this to your search:

... | fieldformat Message=if(length(Message) > 150, substr(Message, 0, 150) + "...", Message)
Get Updates on the Splunk Community!

Cloud Platform | Customer Change Announcement: Email Notification Will Be Available ...

The Notification Team is migrating our email service provider since currently there’s no support ...

Mastering Synthetic Browser Testing: Pro Tips to Keep Your Web App Running Smoothly

To start, if you're new to synthetic monitoring, I recommend exploring this synthetic monitoring overview. In ...

Splunk Edge Processor | Popular Use Cases to Get Started with Edge Processor

Splunk Edge Processor offers more efficient, flexible data transformation – helping you reduce noise, control ...