<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to remove one field to be shown in column chart in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-remove-one-field-to-be-shown-in-column-chart/m-p/391849#M114074</link>
    <description>&lt;P&gt;thanks for your response, but it didnt worked, i mentioned fields in last and in both viz and stats only those fields were shown which were in fields command,&lt;/P&gt;</description>
    <pubDate>Wed, 20 Jun 2018 07:39:26 GMT</pubDate>
    <dc:creator>sindhoo</dc:creator>
    <dc:date>2018-06-20T07:39:26Z</dc:date>
    <item>
      <title>How to remove one field to be shown in column chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-remove-one-field-to-be-shown-in-column-chart/m-p/391845#M114070</link>
      <description>&lt;P&gt;I have created a query which have 4 columns in statistics and want to show column chart as well but with 3 columns. how to remove extra column in statistics?&lt;/P&gt;

&lt;P&gt;base search | stats total count(a) count(b) by Function&lt;/P&gt;

&lt;P&gt;Statistics output is --&amp;gt; &lt;BR /&gt;
Function     Total        count(a)         count(b)&lt;BR /&gt;
Test              10                6                    4&lt;/P&gt;

&lt;P&gt;but in chart i dont want to see column of total, only want to see count of a and b per function but dont want to remove it from statistics. &lt;/P&gt;</description>
      <pubDate>Thu, 14 Jun 2018 10:04:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-remove-one-field-to-be-shown-in-column-chart/m-p/391845#M114070</guid>
      <dc:creator>sindhoo</dc:creator>
      <dc:date>2018-06-14T10:04:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove one field to be shown in column chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-remove-one-field-to-be-shown-in-column-chart/m-p/391846#M114071</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;|fields - Total
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 14 Jun 2018 13:28:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-remove-one-field-to-be-shown-in-column-chart/m-p/391846#M114071</guid>
      <dc:creator>harishalipaka</dc:creator>
      <dc:date>2018-06-14T13:28:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove one field to be shown in column chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-remove-one-field-to-be-shown-in-column-chart/m-p/391847#M114072</link>
      <description>&lt;P&gt;harishalipaka's comment above should work if you add it to the end of your search. For more info on the fields command please see the docs at &lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Fields"&gt;https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Fields&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jun 2018 14:10:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-remove-one-field-to-be-shown-in-column-chart/m-p/391847#M114072</guid>
      <dc:creator>lacastillo</dc:creator>
      <dc:date>2018-06-14T14:10:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove one field to be shown in column chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-remove-one-field-to-be-shown-in-column-chart/m-p/391848#M114073</link>
      <description>&lt;P&gt;thanks for your response, but it didnt worked, i mentioned fields in last and in both viz and stats only those fields were shown which were in fields command,&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jun 2018 07:39:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-remove-one-field-to-be-shown-in-column-chart/m-p/391848#M114073</guid>
      <dc:creator>sindhoo</dc:creator>
      <dc:date>2018-06-20T07:39:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove one field to be shown in column chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-remove-one-field-to-be-shown-in-column-chart/m-p/391849#M114074</link>
      <description>&lt;P&gt;thanks for your response, but it didnt worked, i mentioned fields in last and in both viz and stats only those fields were shown which were in fields command,&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jun 2018 07:39:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-remove-one-field-to-be-shown-in-column-chart/m-p/391849#M114074</guid>
      <dc:creator>sindhoo</dc:creator>
      <dc:date>2018-06-20T07:39:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove one field to be shown in column chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-remove-one-field-to-be-shown-in-column-chart/m-p/391850#M114075</link>
      <description>&lt;P&gt;Can you post the search you used?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jun 2018 19:27:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-remove-one-field-to-be-shown-in-column-chart/m-p/391850#M114075</guid>
      <dc:creator>lacastillo</dc:creator>
      <dc:date>2018-06-28T19:27:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove one field to be shown in column chart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-remove-one-field-to-be-shown-in-column-chart/m-p/391851#M114076</link>
      <description>&lt;P&gt;I am having the same issue. It looks simple enough that this should work but it doesn't. It still keeps TOTAL on my bar chart. It does, however, remove it from statistics table. This is what I am using. How can you remove TOTAL from the charts? I am running version 7.2.0.&lt;/P&gt;

&lt;P&gt;...  |fields - Total&lt;/P&gt;</description>
      <pubDate>Wed, 12 Dec 2018 01:15:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-remove-one-field-to-be-shown-in-column-chart/m-p/391851#M114076</guid>
      <dc:creator>hexxamillion</dc:creator>
      <dc:date>2018-12-12T01:15:34Z</dc:date>
    </item>
  </channel>
</rss>

