Security

Disable or increase truncation of hostnames and timestamp

JensT
Communicator

Hello,

we have longer hostnames. Like "gateway_chvj500ld800.mycompany.net".

Its truncated to something like "gateway_chvj.....mycompany.net" So the important part is missing.

Same with Timestamps.

How can we eliminate the truncation?

Cheers,

Jens

Tags (1)
0 Karma

JensT
Communicator
0 Karma

Simeon
Splunk Employee
Splunk Employee

I don't believe there is an easy way to do it, but I might be wrong. I would create a rex and replace for your hostnames when running reports, similar to what is in this Question:

http://answers.splunk.com/questions/7077/how-can-i-rename-the-host-names-for-my-chart

0 Karma

Genti
Splunk Employee
Splunk Employee

im sure it is in the UI, on the field picker little blue box.
JensT, if you mouse over one of the hosts, or timestamps, you should notice that the timestamp/host is fully there. If you click on one, it will add it correctly to the search query. The truncation is due to the available screen-space as mick points out, and im not sure if there can be done anything against it. I spoke to a UI a while back and seems that is the way it's supposed to be. JV might want to comment on this, if he sees this thread.

Mick
Splunk Employee
Splunk Employee

Are you talking about the actual field being truncated or is it just the way it is displayed in the UI, due to the available screen-space? Any chance to a screenshot?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...