If I run a search and then go to one of the Events in the search results, when I click the Source, I get a window with 3 options: Add to Search, Exclude from Search, and New Search. When I last used Splunk, many versions ago, I was able to open the actually source log file that belonged to an Event. Is there still away to do this?
Thank you
Hi devcs,
If you expand the event (drop down the ">"), then drop down Event Actions, in there you should see "Show Source".
Hi devcs,
If you expand the event (drop down the ">"), then drop down Event Actions, in there you should see "Show Source".
Hi glennpierce ,
How to disable the "Show source" from Event Actions?