Splunk® Enterprise

Getting Data In

Download manual as PDF

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

Set search-time segmentation in Splunk Web

Splunk Web allows you to set segmentation for search results. This has nothing to do with index-time segmentation. Splunk Web segmentation affects browser interaction and can speed up search results.

To set search-result segmentation:

1. Perform a search. Look at the results.

2. Click Format above the returned set of events.

3. In the Drilldown dropdown box, choose from the available options: Full, Inner, Outer, or None. The default is "Full".

You can configure the meaning of these dropdown options, as described in "Set the segmentation for event data".

Set the segmentation for event data
Overview of data preview

This documentation applies to the following versions of Splunk® Enterprise: 6.0

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters