Splunk Search

How can I expand/unfold all fields in all events in list view?

nikosattlermhp
Engager

I have many events as the following in my search: alt text

All fields are collapsed at the beginning and I have to unfold every single field by clicking on the little blue "+" (In the screenshot I aleady clicked on the "+".). You can I get all field unfold directly at the beginning so I don't have to click on every "+"?

Thanks in advance.

0 Karma

sanjeev543
Communicator

If you just want to list all the fields getting extracted, then you can use the fieldsummary command

https://docs.splunk.com/Documentation/Splunk/7.3.2/SearchReference/Fieldsummary

Or if the question is to expand the event view please refer below URL

https://answers.splunk.com/answers/559/how-do-you-tweak-splunk-to-display-an-event-that-is-more-than...

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...