Set search-time event segmentation in Splunk Web
Splunk Web allows you to set segmentation for search results. While this has nothing to do with index-time segmentation, search-time segmentation in Splunk Web affects browser interaction and can speed up search results.
To set search-result segmentation:
1. Perform a search. Look at the results.
2. Click Options... above the returned set of events.
3. In the Event Segmentation dropdown box, choose from the available options: full, inner, outer, or raw. The default is "full".
You can configure the meaning of these dropdown options, as described in "Set the segmentation for event data".
Set the segmentation for event data
Use a test index to test your inputs
This documentation applies to the following versions of Splunk® Enterprise: 6.5.7, 9.0.0