<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to get logs to show fieldnames in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-logs-to-show-fieldnames/m-p/635610#M220825</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/253386"&gt;@NJ&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;are you using Verbose or Smart Mode in your search?&lt;/P&gt;&lt;P&gt;you have to use Verbose Mode to display all the extracted fields.&lt;/P&gt;&lt;P&gt;if you have in interesting fields less fields than all fields the reason is that probably you have less results than 20%, so they aren't visualized in interesting fields.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Thu, 23 Mar 2023 05:22:06 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-03-23T05:22:06Z</dc:date>
    <item>
      <title>How to get logs to show fieldnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-logs-to-show-fieldnames/m-p/635579#M220821</link>
      <description>&lt;P&gt;Hi everyone!&lt;/P&gt;&lt;P&gt;I'm still fairly new to Splunk so sorry if it is a simple question.&lt;/P&gt;&lt;P&gt;I have some logs that does not show the field names when you have done a search.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NJ_0-1679533670406.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/24448iF034E403044590CB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="NJ_0-1679533670406.png" alt="NJ_0-1679533670406.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;But when I expand the event, I can see the names.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NJ_1-1679533720795.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/24449iD57B1156160CDB3B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="NJ_1-1679533720795.png" alt="NJ_1-1679533720795.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it not possible to have the field names shown in the first picture?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 01:09:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-logs-to-show-fieldnames/m-p/635579#M220821</guid>
      <dc:creator>NJ</dc:creator>
      <dc:date>2023-03-23T01:09:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to get logs to show fieldnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-logs-to-show-fieldnames/m-p/635588#M220822</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/253386"&gt;@NJ&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;The &lt;EM&gt;List&lt;/EM&gt; view will just show you what the event data looks like as it was ingested.&amp;nbsp; There obviously must be some automatic field extraction going on for the field values to be extracted.&lt;BR /&gt;&lt;BR /&gt;If you want column headers (field names) to show with the values underneath, then you can pick the table view instead&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="yeahnah_0-1679538669808.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/24452iA548C67D9080B681/image-size/medium?v=v2&amp;amp;px=400" role="button" title="yeahnah_0-1679538669808.png" alt="yeahnah_0-1679538669808.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Whatever you have as &lt;EM&gt;Selected Fields&lt;/EM&gt; will show as a column with the value underneath.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="yeahnah_1-1679538705632.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/24453iB6A979CD51943F3C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="yeahnah_1-1679538705632.png" alt="yeahnah_1-1679538705632.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;You can select or deselect fields by clicking into them.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="yeahnah_2-1679538807545.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/24454iF58EAA34FCB93F13/image-size/medium?v=v2&amp;amp;px=400" role="button" title="yeahnah_2-1679538807545.png" alt="yeahnah_2-1679538807545.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Another method, though is to use the table command&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;...your search ...
| table *&lt;/LI-CODE&gt;&lt;P&gt;You can specify the field names you want or just use the * wildcard for everything.&lt;BR /&gt;&lt;BR /&gt;Hope this helps.&amp;nbsp; Please mark as solution provided if this answer your query.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 02:36:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-logs-to-show-fieldnames/m-p/635588#M220822</guid>
      <dc:creator>yeahnah</dc:creator>
      <dc:date>2023-03-23T02:36:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to get logs to show fieldnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-logs-to-show-fieldnames/m-p/635593#M220823</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/158935"&gt;@yeahnah&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply learned something new!&lt;/P&gt;&lt;P&gt;However, is there no way to get it like this JSON example:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NJ_0-1679541176917.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/24455iC2C4308BFEBBF7BC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="NJ_0-1679541176917.png" alt="NJ_0-1679541176917.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 03:13:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-logs-to-show-fieldnames/m-p/635593#M220823</guid>
      <dc:creator>NJ</dc:creator>
      <dc:date>2023-03-23T03:13:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to get logs to show fieldnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-logs-to-show-fieldnames/m-p/635602#M220824</link>
      <description>&lt;P&gt;Yes, you can do that using a search command, like this&lt;/P&gt;&lt;PRE&gt;... your base search ...&lt;BR /&gt;| fields *&lt;BR /&gt;| tojson&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 03:54:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-logs-to-show-fieldnames/m-p/635602#M220824</guid>
      <dc:creator>yeahnah</dc:creator>
      <dc:date>2023-03-23T03:54:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to get logs to show fieldnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-logs-to-show-fieldnames/m-p/635610#M220825</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/253386"&gt;@NJ&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;are you using Verbose or Smart Mode in your search?&lt;/P&gt;&lt;P&gt;you have to use Verbose Mode to display all the extracted fields.&lt;/P&gt;&lt;P&gt;if you have in interesting fields less fields than all fields the reason is that probably you have less results than 20%, so they aren't visualized in interesting fields.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 05:22:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-logs-to-show-fieldnames/m-p/635610#M220825</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-03-23T05:22:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to get logs to show fieldnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-logs-to-show-fieldnames/m-p/635611#M220826</link>
      <description>&lt;P&gt;Just be aware that you're not showing the original event anymore - just some rendered json structure.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 05:30:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-logs-to-show-fieldnames/m-p/635611#M220826</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-03-23T05:30:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to get logs to show fieldnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-logs-to-show-fieldnames/m-p/635613#M220827</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see the field names on the left side but I was wondering if I would be able to see them in the event list like this:&lt;/P&gt;&lt;P&gt;Field name: Value&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NJ_0-1679549675586.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/24458i4124FD21E9D2CE6A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="NJ_0-1679549675586.png" alt="NJ_0-1679549675586.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 05:35:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-logs-to-show-fieldnames/m-p/635613#M220827</guid>
      <dc:creator>NJ</dc:creator>
      <dc:date>2023-03-23T05:35:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to get logs to show fieldnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-logs-to-show-fieldnames/m-p/635618#M220830</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/253386"&gt;@NJ&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;you can visualize logs in raw text mode.&lt;/P&gt;&lt;P&gt;If you want to visualize them in json format, you have to manually open each of them, for my knowledge there isn't an option to open all the sub parts of the log.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 06:00:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-logs-to-show-fieldnames/m-p/635618#M220830</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-03-23T06:00:33Z</dc:date>
    </item>
  </channel>
</rss>

