<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: REMOVE AN EXTRA FIELD in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/REMOVE-AN-EXTRA-FIELD/m-p/525366#M148241</link>
    <description>&lt;P&gt;replace your search command just before timechart with below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| search business_field=* NOT business_field=Results&lt;/LI-CODE&gt;&lt;P&gt;if you think you have got 100% matches for field business_field extracted using rex command the below search would be enough. no need to say business_field=* ( this is useful to ignore null values in events&amp;nbsp; if there are any events they are not matched&amp;nbsp; for regex and returned null values)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| search NOT business_field=Results​&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 19 Oct 2020 14:00:18 GMT</pubDate>
    <dc:creator>thambisetty</dc:creator>
    <dc:date>2020-10-19T14:00:18Z</dc:date>
    <item>
      <title>REMOVE AN EXTRA FIELD</title>
      <link>https://community.splunk.com/t5/Splunk-Search/REMOVE-AN-EXTRA-FIELD/m-p/525347#M148233</link>
      <description>&lt;P&gt;i have regular expression that i use to extract the below words, but i dont want to show the Results fiels or column, how do i exclude it?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ive tried&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | fields -Results&amp;nbsp; &amp;amp; it didnt work&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sphiwee_0-1603112079235.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/11355i88A5BCAC9B4D9625/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sphiwee_0-1603112079235.png" alt="sphiwee_0-1603112079235.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 12:58:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/REMOVE-AN-EXTRA-FIELD/m-p/525347#M148233</guid>
      <dc:creator>sphiwee</dc:creator>
      <dc:date>2020-10-19T12:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: REMOVE AN EXTRA FIELD</title>
      <link>https://community.splunk.com/t5/Splunk-Search/REMOVE-AN-EXTRA-FIELD/m-p/525350#M148235</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223364"&gt;@sphiwee&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;put a space between - and the field name&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| fields - Results&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 13:04:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/REMOVE-AN-EXTRA-FIELD/m-p/525350#M148235</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-10-19T13:04:32Z</dc:date>
    </item>
    <item>
      <title>Re: REMOVE AN EXTRA FIELD</title>
      <link>https://community.splunk.com/t5/Splunk-Search/REMOVE-AN-EXTRA-FIELD/m-p/525351#M148236</link>
      <description>&lt;P&gt;share your query to understand if Results appeared in chart&amp;nbsp; has derived from another field.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 13:12:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/REMOVE-AN-EXTRA-FIELD/m-p/525351#M148236</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-10-19T13:12:10Z</dc:date>
    </item>
    <item>
      <title>Re: REMOVE AN EXTRA FIELD</title>
      <link>https://community.splunk.com/t5/Splunk-Search/REMOVE-AN-EXTRA-FIELD/m-p/525352#M148237</link>
      <description>&lt;P&gt;Still not working&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 13:15:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/REMOVE-AN-EXTRA-FIELD/m-p/525352#M148237</guid>
      <dc:creator>sphiwee</dc:creator>
      <dc:date>2020-10-19T13:15:34Z</dc:date>
    </item>
    <item>
      <title>Re: REMOVE AN EXTRA FIELD</title>
      <link>https://community.splunk.com/t5/Splunk-Search/REMOVE-AN-EXTRA-FIELD/m-p/525356#M148238</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sphiwee_0-1603113586356.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/11356iB91BFEF8F1763B09/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sphiwee_0-1603113586356.png" alt="sphiwee_0-1603113586356.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Heres the query, i want to remove the far right field "Results"&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 13:20:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/REMOVE-AN-EXTRA-FIELD/m-p/525356#M148238</guid>
      <dc:creator>sphiwee</dc:creator>
      <dc:date>2020-10-19T13:20:59Z</dc:date>
    </item>
    <item>
      <title>Re: REMOVE AN EXTRA FIELD</title>
      <link>https://community.splunk.com/t5/Splunk-Search/REMOVE-AN-EXTRA-FIELD/m-p/525359#M148239</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223364"&gt;@sphiwee&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;sorry, I misunderstood!&lt;/P&gt;&lt;P&gt;Try adding to the last "search command" also&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;NOT business_field="Results"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;P.S.: you don't need "AND" operator in search.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 13:31:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/REMOVE-AN-EXTRA-FIELD/m-p/525359#M148239</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-10-19T13:31:17Z</dc:date>
    </item>
    <item>
      <title>Re: REMOVE AN EXTRA FIELD</title>
      <link>https://community.splunk.com/t5/Splunk-Search/REMOVE-AN-EXTRA-FIELD/m-p/525363#M148240</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sphiwee_0-1603114675448.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/11358i176024A41977C414/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sphiwee_0-1603114675448.png" alt="sphiwee_0-1603114675448.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Still not working, now receiving an error&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 13:38:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/REMOVE-AN-EXTRA-FIELD/m-p/525363#M148240</guid>
      <dc:creator>sphiwee</dc:creator>
      <dc:date>2020-10-19T13:38:16Z</dc:date>
    </item>
    <item>
      <title>Re: REMOVE AN EXTRA FIELD</title>
      <link>https://community.splunk.com/t5/Splunk-Search/REMOVE-AN-EXTRA-FIELD/m-p/525366#M148241</link>
      <description>&lt;P&gt;replace your search command just before timechart with below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| search business_field=* NOT business_field=Results&lt;/LI-CODE&gt;&lt;P&gt;if you think you have got 100% matches for field business_field extracted using rex command the below search would be enough. no need to say business_field=* ( this is useful to ignore null values in events&amp;nbsp; if there are any events they are not matched&amp;nbsp; for regex and returned null values)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| search NOT business_field=Results​&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 14:00:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/REMOVE-AN-EXTRA-FIELD/m-p/525366#M148241</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-10-19T14:00:18Z</dc:date>
    </item>
    <item>
      <title>Re: REMOVE AN EXTRA FIELD</title>
      <link>https://community.splunk.com/t5/Splunk-Search/REMOVE-AN-EXTRA-FIELD/m-p/525369#M148243</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223364"&gt;@sphiwee&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;sorry I wasn't clear, in your search&amp;nbsp;replace&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| search business_field=* AND "status:COMPLETED"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;with&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| search business_field=* "status:COMPLETED" NOT business_field="Results"&lt;/LI-CODE&gt;&lt;P&gt;and do not use more the field command.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 13:59:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/REMOVE-AN-EXTRA-FIELD/m-p/525369#M148243</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-10-19T13:59:42Z</dc:date>
    </item>
    <item>
      <title>Re: REMOVE AN EXTRA FIELD</title>
      <link>https://community.splunk.com/t5/Splunk-Search/REMOVE-AN-EXTRA-FIELD/m-p/525373#M148244</link>
      <description>&lt;P&gt;&lt;EM&gt;still not working&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sphiwee_0-1603116274868.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/11359iC3EC18725870D675/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sphiwee_0-1603116274868.png" alt="sphiwee_0-1603116274868.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 14:04:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/REMOVE-AN-EXTRA-FIELD/m-p/525373#M148244</guid>
      <dc:creator>sphiwee</dc:creator>
      <dc:date>2020-10-19T14:04:52Z</dc:date>
    </item>
    <item>
      <title>Re: REMOVE AN EXTRA FIELD</title>
      <link>https://community.splunk.com/t5/Splunk-Search/REMOVE-AN-EXTRA-FIELD/m-p/525375#M148245</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223364"&gt;@sphiwee&lt;/a&gt;&amp;nbsp;whats your current search query?&amp;nbsp;you can not use "business_field=Results" inside the fields command.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 14:09:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/REMOVE-AN-EXTRA-FIELD/m-p/525375#M148245</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2020-10-19T14:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: REMOVE AN EXTRA FIELD</title>
      <link>https://community.splunk.com/t5/Splunk-Search/REMOVE-AN-EXTRA-FIELD/m-p/525376#M148246</link>
      <description>&lt;P&gt;can you try below command after rex command and check if you see field business_field and value Results. if you don't see that means there could be white space added at starting or ending of Results value.&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| search business_field=* NOT business_field=Results
| stats count by business_field
| search business_field=*Results*&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;you can try below to make sure there is white space.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| search business_field=* NOT business_field=Results
| stats count by business_field
| search business_field=*Results*&lt;/LI-CODE&gt;&lt;P&gt;if above search works then you can try below in your actual search&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| search business_field=* NOT business_field=*Results*&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 14:11:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/REMOVE-AN-EXTRA-FIELD/m-p/525376#M148246</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-10-19T14:11:19Z</dc:date>
    </item>
    <item>
      <title>Re: REMOVE AN EXTRA FIELD</title>
      <link>https://community.splunk.com/t5/Splunk-Search/REMOVE-AN-EXTRA-FIELD/m-p/525377#M148247</link>
      <description>&lt;P&gt;here is my query&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/80737"&gt;@inventsekar&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 14:12:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/REMOVE-AN-EXTRA-FIELD/m-p/525377#M148247</guid>
      <dc:creator>sphiwee</dc:creator>
      <dc:date>2020-10-19T14:12:45Z</dc:date>
    </item>
    <item>
      <title>Re: REMOVE AN EXTRA FIELD</title>
      <link>https://community.splunk.com/t5/Splunk-Search/REMOVE-AN-EXTRA-FIELD/m-p/525378#M148248</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223364"&gt;@sphiwee&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;could you try to execute the last search in verbose mode?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 14:15:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/REMOVE-AN-EXTRA-FIELD/m-p/525378#M148248</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-10-19T14:15:15Z</dc:date>
    </item>
  </channel>
</rss>

