<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Table showing fields from excluded events after head in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Table-showing-fields-from-excluded-events-after-head/m-p/685570#M233922</link>
    <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Splunk_search_fields1.jpg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30574iAA81B626B8A03F29/image-size/large?v=v2&amp;amp;px=999" role="button" title="Splunk_search_fields1.jpg" alt="Splunk_search_fields1.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 26 Apr 2024 05:20:17 GMT</pubDate>
    <dc:creator>plapila</dc:creator>
    <dc:date>2024-04-26T05:20:17Z</dc:date>
    <item>
      <title>Table showing fields from excluded events after head</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Table-showing-fields-from-excluded-events-after-head/m-p/685551#M233918</link>
      <description>&lt;P&gt;Is this intended behavior?&lt;/P&gt;&lt;P&gt;After selecting only a single event with "head 1" fields from excluded events that occurred at the same time can be seen in a table when using wildcards in example "table _time,tags.* values.*"&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2024 04:15:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Table-showing-fields-from-excluded-events-after-head/m-p/685551#M233918</guid>
      <dc:creator>plapila</dc:creator>
      <dc:date>2024-04-26T04:15:19Z</dc:date>
    </item>
    <item>
      <title>Re: Table showing fields from excluded events after head</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Table-showing-fields-from-excluded-events-after-head/m-p/685555#M233920</link>
      <description>&lt;P&gt;You need to qualify your question with dataset (mockup or sanitized), SPL, and results. &amp;nbsp;I cannot reproduce what you described based on my mind-reading of your question. &amp;nbsp;But you must not rely on volunteers reading your mind. (It is never good to force people to read your mind.)&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2024 04:57:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Table-showing-fields-from-excluded-events-after-head/m-p/685555#M233920</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-04-26T04:57:46Z</dc:date>
    </item>
    <item>
      <title>Re: Table showing fields from excluded events after head</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Table-showing-fields-from-excluded-events-after-head/m-p/685561#M233921</link>
      <description>&lt;P&gt;Screencaptures for clarification&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Splunk_search_fields1.jpg"&gt;&lt;img src="https://community.splunk.com/skins/images/FAE98A0A1109460D72C2D795DC4120FD/responsive_peak/images/image_not_found.png" alt="Splunk_search_fields1.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Splunk_search_fields2.jpg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30572i99A596B5A289CD3B/image-size/large?v=v2&amp;amp;px=999" role="button" title="Splunk_search_fields2.jpg" alt="Splunk_search_fields2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2024 05:08:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Table-showing-fields-from-excluded-events-after-head/m-p/685561#M233921</guid>
      <dc:creator>plapila</dc:creator>
      <dc:date>2024-04-26T05:08:40Z</dc:date>
    </item>
    <item>
      <title>Re: Table showing fields from excluded events after head</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Table-showing-fields-from-excluded-events-after-head/m-p/685570#M233922</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Splunk_search_fields1.jpg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30574iAA81B626B8A03F29/image-size/large?v=v2&amp;amp;px=999" role="button" title="Splunk_search_fields1.jpg" alt="Splunk_search_fields1.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2024 05:20:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Table-showing-fields-from-excluded-events-after-head/m-p/685570#M233922</guid>
      <dc:creator>plapila</dc:creator>
      <dc:date>2024-04-26T05:20:17Z</dc:date>
    </item>
    <item>
      <title>Re: Table showing fields from excluded events after head</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Table-showing-fields-from-excluded-events-after-head/m-p/685574#M233924</link>
      <description>&lt;P&gt;OK, I can see what you mean now. &amp;nbsp;And I can confirm with this emulation&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults format=csv data="a,b,c,d
va,vb
,,vc,vd"
| head 1&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;a&lt;/TD&gt;&lt;TD&gt;b&lt;/TD&gt;&lt;TD&gt;c&lt;/TD&gt;&lt;TD&gt;d&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;va&lt;/TD&gt;&lt;TD&gt;vb&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;With little information from its &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Head" target="_blank" rel="noopener"&gt;official documentation&lt;/A&gt;, I can argue either way as to this is a feature or a bug. &amp;nbsp;But you must have a use case in mind. &amp;nbsp;How will head be used in your application, and what is your expected result?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2024 06:19:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Table-showing-fields-from-excluded-events-after-head/m-p/685574#M233924</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-04-26T06:19:01Z</dc:date>
    </item>
    <item>
      <title>Re: Table showing fields from excluded events after head</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Table-showing-fields-from-excluded-events-after-head/m-p/685575#M233925</link>
      <description>&lt;P&gt;Yes, unfortunately this is the way it works - I have never fully worked out why this is the case - but most of the time it doesn't really matter as - I have used techniques to solve this where I needed to only get the fields that pertained to the particular event, but that involved quite a bit of other work&lt;/P&gt;&lt;P&gt;You can do something simple like&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;search bla
| transpose 0
| where isnotnull('row 1')
| transpose 0 header_field=column
| fields - column&lt;/LI-CODE&gt;&lt;P&gt;If this is just about data investigation and looking for things.&lt;/P&gt;&lt;P&gt;Give us more on any use case where this is an issue and we can see if there is a way to solve it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2024 06:22:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Table-showing-fields-from-excluded-events-after-head/m-p/685575#M233925</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2024-04-26T06:22:16Z</dc:date>
    </item>
  </channel>
</rss>

