<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to list field and their values? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-list-field-and-their-values/m-p/563102#M196191</link>
    <description>&lt;P&gt;Are you just trying to find out what fields are available?&lt;BR /&gt;If so you can simply run the following and look at the table or click on "events" to see all the fields.&lt;BR /&gt;(Use "head" to limit the results or choose a short time span with the time picker so that you dont get back the entire result set.)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=your_index_name |head 100 |table *&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 12 Aug 2021 16:59:26 GMT</pubDate>
    <dc:creator>codebuilder</dc:creator>
    <dc:date>2021-08-12T16:59:26Z</dc:date>
    <item>
      <title>How to list field and their values?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-list-field-and-their-values/m-p/562952#M196144</link>
      <description>&lt;P&gt;&lt;SPAN class="key-name"&gt;My log is formatted like this:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="key-name"&gt;labels&lt;/SPAN&gt;&lt;SPAN&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;{&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-3"&gt;&lt;SPAN class="key-name"&gt;app&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string"&gt;splunk-kubernetes-metrics&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-3"&gt;&lt;SPAN class="key-name"&gt;app.kubernetes.io/managed-by&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string"&gt;Helm&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-3"&gt;&lt;SPAN class="key-name"&gt;chart&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string"&gt;splunk-kubernetes-metrics-1.4.1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-3"&gt;&lt;SPAN class="key-name"&gt;engine&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string"&gt;fluentd&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-3"&gt;&lt;SPAN class="key-name"&gt;heritage&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string"&gt;Helm&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class="key level-3"&gt;&lt;SPAN class="key-name"&gt;release&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class="t string"&gt;splunk-monitor&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;How do I find a list of fields and their values?&amp;nbsp;I want to list all the values in field labels.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2021 15:24:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-list-field-and-their-values/m-p/562952#M196144</guid>
      <dc:creator>truongvinh2112</dc:creator>
      <dc:date>2021-08-11T15:24:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to list field and their values?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-list-field-and-their-values/m-p/562957#M196148</link>
      <description>&lt;LI-CODE lang="markup"&gt;| extract
| rename labels.* as *&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 11 Aug 2021 15:50:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-list-field-and-their-values/m-p/562957#M196148</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-08-11T15:50:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to list field and their values?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-list-field-and-their-values/m-p/563015#M196152</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="truongvinh2112_0-1628738260650.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15539i4F07A4650FA67045/image-size/medium?v=v2&amp;amp;px=400" role="button" title="truongvinh2112_0-1628738260650.png" alt="truongvinh2112_0-1628738260650.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="truongvinh2112_1-1628738377408.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15540i760A43D9A34EEDF0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="truongvinh2112_1-1628738377408.png" alt="truongvinh2112_1-1628738377408.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I'm trying to build a K8s dashboard on Splunk. I tried your way but not working. Can you be more specific?&lt;/P&gt;&lt;P&gt;The image above is an example.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 03:22:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-list-field-and-their-values/m-p/563015#M196152</guid>
      <dc:creator>truongvinh2112</dc:creator>
      <dc:date>2021-08-12T03:22:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to list field and their values?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-list-field-and-their-values/m-p/563023#M196155</link>
      <description>&lt;P&gt;Sure. What do these images represent? What did you get when you tried my suggestion? Can you share the raw events in a code block &amp;lt;/&amp;gt; so we can see what you are dealing with and try some tests?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 06:04:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-list-field-and-their-values/m-p/563023#M196155</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-08-12T06:04:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to list field and their values?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-list-field-and-their-values/m-p/563102#M196191</link>
      <description>&lt;P&gt;Are you just trying to find out what fields are available?&lt;BR /&gt;If so you can simply run the following and look at the table or click on "events" to see all the fields.&lt;BR /&gt;(Use "head" to limit the results or choose a short time span with the time picker so that you dont get back the entire result set.)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=your_index_name |head 100 |table *&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 16:59:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-list-field-and-their-values/m-p/563102#M196191</guid>
      <dc:creator>codebuilder</dc:creator>
      <dc:date>2021-08-12T16:59:26Z</dc:date>
    </item>
  </channel>
</rss>

