I have a jmx sourcetype that has several 100s of lines of metrics. When these are ingested into splunk, I see only a few lines from these events in the _raw and nothing of use to me in any other fields
I see the full 400 odd lines when I click on EventActions->ShowSource on each event. These "hidden" lines are the ones that I am most interested in but they are not searchable in splunk.
What is the reason for this not being a part of _raw? How can I fix this please?
Thanks
What are your inputs.conf and props.conf settings for this data? I'm guessing the data either get's truncated, or split into separate events (part of which are out of sight because of lack of proper timestamping or so perhaps)?
Can you share a (partial) sample of what the data looks like and a screenshot of how it shows up in Splunk?