Getting Data In

_raw doesn't have the full event data that I see by clicking the menu EventActions->ShowSource on each search result

splunkering
Explorer

I have a jmx sourcetype that has several 100s of lines of metrics. When these are ingested into splunk, I see only a few lines from these events in the _raw and nothing of use to me in any other fields
I see the full 400 odd lines when I click on EventActions->ShowSource on each event. These "hidden" lines are the ones that I am most interested in but they are not searchable in splunk.

What is the reason for this not being a part of _raw? How can I fix this please?

Thanks

Tags (1)
0 Karma

FrankVl
Ultra Champion

What are your inputs.conf and props.conf settings for this data? I'm guessing the data either get's truncated, or split into separate events (part of which are out of sight because of lack of proper timestamping or so perhaps)?

Can you share a (partial) sample of what the data looks like and a screenshot of how it shows up in Splunk?

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...