![]() By default, the limit for the number of fields that can be extracted automatically at search time is 100. While Splunk software has indexed all of the fields correctly, this anomaly occurs because of a configuration setting for how Splunk software extracts the fields at search time.īefore Splunk software displays fields in Splunk Web, it must first extract those fields by performing a search time field extraction. If you index a structured data file with a large number of columns (for example, a CSV file with 300 columns), you might experience a problem later where the Search app does not appear to return or display all of the fields for that file. Structured data files with large numbers of columns might not display all extracted fields in Splunk Search ![]()
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |