I have some JSON data being fed into splunk which contains data nested a few levels deep. In search with syntax highlighting, Splunk pretty-prints the data and automatically collapses the second-level.
The problem:
I can expand the nested structure just fine in a non-real-time search, but whenever I expand the structure in a real-time search, it expands for a brief moment, and then collapses itself again.
This is with Splunk 5.0
Make sure you hit pause in Real Time if you want to expand an view.