<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there an alternative to fieldsummary to show field names for an index? in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Is-there-an-alternative-to-fieldsummary-to-show-field-names-for/m-p/284435#M2649</link>
    <description>&lt;P&gt;Hi&lt;BR /&gt;
Use this for example , it will do what you want&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal|fields + *|transpose|table column
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;OR&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=main|fields + *|transpose|rename column as field|table field
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Thu, 18 Feb 2016 10:20:29 GMT</pubDate>
    <dc:creator>chimell</dc:creator>
    <dc:date>2016-02-18T10:20:29Z</dc:date>
    <item>
      <title>Is there an alternative to fieldsummary to show field names for an index?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Is-there-an-alternative-to-fieldsummary-to-show-field-names-for/m-p/284434#M2648</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;My search looks like:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; mysearch....[ index=adc| fieldsummary | fields field]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Is there a command to display the fieldnames (field) of an index without using the &lt;CODE&gt;fieldsummary&lt;/CODE&gt; command? Or an option for &lt;CODE&gt;fieldsummary&lt;/CODE&gt; to just return field?&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;fieldsummary&lt;/CODE&gt; is to extensive and takes to much time.&lt;/P&gt;

&lt;P&gt;Thank you &lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2016 09:59:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Is-there-an-alternative-to-fieldsummary-to-show-field-names-for/m-p/284434#M2648</guid>
      <dc:creator>dkeck</dc:creator>
      <dc:date>2016-02-18T09:59:38Z</dc:date>
    </item>
    <item>
      <title>Re: Is there an alternative to fieldsummary to show field names for an index?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Is-there-an-alternative-to-fieldsummary-to-show-field-names-for/m-p/284435#M2649</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;
Use this for example , it will do what you want&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal|fields + *|transpose|table column
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;OR&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=main|fields + *|transpose|rename column as field|table field
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 18 Feb 2016 10:20:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Is-there-an-alternative-to-fieldsummary-to-show-field-names-for/m-p/284435#M2649</guid>
      <dc:creator>chimell</dc:creator>
      <dc:date>2016-02-18T10:20:29Z</dc:date>
    </item>
    <item>
      <title>Re: Is there an alternative to fieldsummary to show field names for an index?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Is-there-an-alternative-to-fieldsummary-to-show-field-names-for/m-p/284436#M2650</link>
      <description>&lt;P&gt;This is not faster. It still goes to disk and searches events.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2016 10:25:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Is-there-an-alternative-to-fieldsummary-to-show-field-names-for/m-p/284436#M2650</guid>
      <dc:creator>jeffland</dc:creator>
      <dc:date>2016-02-18T10:25:03Z</dc:date>
    </item>
    <item>
      <title>Re: Is there an alternative to fieldsummary to show field names for an index?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Is-there-an-alternative-to-fieldsummary-to-show-field-names-for/m-p/284437#M2651</link>
      <description>&lt;P&gt;Awesome thank you &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2016 10:31:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Is-there-an-alternative-to-fieldsummary-to-show-field-names-for/m-p/284437#M2651</guid>
      <dc:creator>dkeck</dc:creator>
      <dc:date>2016-02-18T10:31:27Z</dc:date>
    </item>
    <item>
      <title>Re: Is there an alternative to fieldsummary to show field names for an index?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Is-there-an-alternative-to-fieldsummary-to-show-field-names-for/m-p/284438#M2652</link>
      <description>&lt;P&gt;thanks . please dont forget to vote&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2016 10:34:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Is-there-an-alternative-to-fieldsummary-to-show-field-names-for/m-p/284438#M2652</guid>
      <dc:creator>chimell</dc:creator>
      <dc:date>2016-02-18T10:34:42Z</dc:date>
    </item>
    <item>
      <title>Re: Is there an alternative to fieldsummary to show field names for an index?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Is-there-an-alternative-to-fieldsummary-to-show-field-names-for/m-p/284439#M2653</link>
      <description>&lt;P&gt;I have a process setup in the Data Curator app that will periodically go through your data and update a lookup that has sourcetypes and field names. This was done pre KV stores which would be a better process /shrug. At any rate the base query is&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;earliest=-45s index=asc_tech | regex sourcetype!="(-\d+$|-too_small$)" | dedup sourcetype | fields - _raw date_* index linecount punct eventtype time*pos splunk_server timestamp host source tag* _* | foreach * [eval &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt; = if(isnotnull('&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'), sourcetype, null())] | stats values(*) as * | transpose | rename "row 1" as sourcetype column as field | makemv delim=" " sourcetype | mvexpand sourcetype | where field!="sourcetype"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;With the lookup method the data is quick go through and the process to keep it update runs in the background. With that in place I've done thing like compare the fields to what is called out in the CIM etc. For example (&lt;A href="http://runals.blogspot.com/2015/10/moving-toward-splunks-cim.html#more"&gt;link&lt;/A&gt;)&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2016 18:18:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Is-there-an-alternative-to-fieldsummary-to-show-field-names-for/m-p/284439#M2653</guid>
      <dc:creator>Runals</dc:creator>
      <dc:date>2016-02-18T18:18:28Z</dc:date>
    </item>
    <item>
      <title>Re: Is there an alternative to fieldsummary to show field names for an index?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Is-there-an-alternative-to-fieldsummary-to-show-field-names-for/m-p/284440#M2654</link>
      <description>&lt;P&gt;Thank you for your reply. I will try that.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Feb 2016 09:25:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Is-there-an-alternative-to-fieldsummary-to-show-field-names-for/m-p/284440#M2654</guid>
      <dc:creator>dkeck</dc:creator>
      <dc:date>2016-02-19T09:25:23Z</dc:date>
    </item>
  </channel>
</rss>

