<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I hide '_time'  field from report table? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-hide-time-field-from-report-table/m-p/742108#M240769</link>
    <description>&lt;P&gt;I'm using a Classic Dashboard. This is my XML:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;event&amp;gt;
	&amp;lt;search&amp;gt;
		&amp;lt;query&amp;gt;index=index 
		| fields - _time
		| table ApplicationName, ApplicationPath, LastRun&amp;lt;/query&amp;gt;
	&amp;lt;/search&amp;gt;
	&amp;lt;fields&amp;gt;ApplicationName, ApplicationPath, LastRun&amp;lt;/fields&amp;gt;
	&amp;lt;option name="type"&amp;gt;table&amp;lt;/option&amp;gt;
&amp;lt;/event&amp;gt;&lt;/LI-CODE&gt;</description>
    <pubDate>Tue, 18 Mar 2025 14:49:38 GMT</pubDate>
    <dc:creator>lcguilfoil</dc:creator>
    <dc:date>2025-03-18T14:49:38Z</dc:date>
    <item>
      <title>How can I hide '_time'  field from report table?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-hide-time-field-from-report-table/m-p/614166#M213430</link>
      <description />
      <pubDate>Thu, 22 Sep 2022 15:46:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-hide-time-field-from-report-table/m-p/614166#M213430</guid>
      <dc:creator>wanda619</dc:creator>
      <dc:date>2022-09-22T15:46:26Z</dc:date>
    </item>
    <item>
      <title>Re: How can I hide '_time'  field from report table?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-hide-time-field-from-report-table/m-p/614178#M213432</link>
      <description>&lt;P&gt;&lt;FONT face="courier new,courier"&gt;| fields - _time&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 16:46:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-hide-time-field-from-report-table/m-p/614178#M213432</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-09-22T16:46:56Z</dc:date>
    </item>
    <item>
      <title>Re: How can I hide '_time'  field from report table?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-hide-time-field-from-report-table/m-p/742106#M240767</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;This removes the values of _time, but not the column header for me. Any ideas?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2025 14:43:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-hide-time-field-from-report-table/m-p/742106#M240767</guid>
      <dc:creator>lcguilfoil</dc:creator>
      <dc:date>2025-03-18T14:43:47Z</dc:date>
    </item>
    <item>
      <title>Re: How can I hide '_time'  field from report table?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-hide-time-field-from-report-table/m-p/742107#M240768</link>
      <description>&lt;P&gt;Please share your query so we can see how you're creating the column header.&amp;nbsp; I suspect you need to remove "_time" from the &lt;FONT face="courier new,courier"&gt;table&lt;/FONT&gt; command.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2025 14:46:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-hide-time-field-from-report-table/m-p/742107#M240768</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2025-03-18T14:46:10Z</dc:date>
    </item>
    <item>
      <title>Re: How can I hide '_time'  field from report table?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-hide-time-field-from-report-table/m-p/742108#M240769</link>
      <description>&lt;P&gt;I'm using a Classic Dashboard. This is my XML:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;event&amp;gt;
	&amp;lt;search&amp;gt;
		&amp;lt;query&amp;gt;index=index 
		| fields - _time
		| table ApplicationName, ApplicationPath, LastRun&amp;lt;/query&amp;gt;
	&amp;lt;/search&amp;gt;
	&amp;lt;fields&amp;gt;ApplicationName, ApplicationPath, LastRun&amp;lt;/fields&amp;gt;
	&amp;lt;option name="type"&amp;gt;table&amp;lt;/option&amp;gt;
&amp;lt;/event&amp;gt;&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 18 Mar 2025 14:49:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-hide-time-field-from-report-table/m-p/742108#M240769</guid>
      <dc:creator>lcguilfoil</dc:creator>
      <dc:date>2025-03-18T14:49:38Z</dc:date>
    </item>
    <item>
      <title>Re: How can I hide '_time'  field from report table?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-hide-time-field-from-report-table/m-p/742114#M240772</link>
      <description>&lt;P&gt;I was able to eliminate the _time column by changing the &lt;FONT face="courier new,courier"&gt;event&lt;/FONT&gt; tag to a &lt;FONT face="courier new,courier"&gt;table&lt;/FONT&gt; tag.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=_internal
		| fields - _time
		| table ApplicationName, ApplicationPath, LastRun&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;$earliest$&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;$latest$&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
        &amp;lt;fields&amp;gt;["ApplicationName","ApplicationPath","LastRun"]&amp;lt;/fields&amp;gt;
      &amp;lt;/table&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2025 15:20:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-hide-time-field-from-report-table/m-p/742114#M240772</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2025-03-18T15:20:04Z</dc:date>
    </item>
    <item>
      <title>Re: How can I hide '_time'  field from report table?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-hide-time-field-from-report-table/m-p/742127#M240777</link>
      <description>&lt;P&gt;Hi, I'd like to keep it an event and not a table.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2025 16:47:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-hide-time-field-from-report-table/m-p/742127#M240777</guid>
      <dc:creator>lcguilfoil</dc:creator>
      <dc:date>2025-03-18T16:47:47Z</dc:date>
    </item>
    <item>
      <title>Re: How can I hide '_time'  field from report table?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-hide-time-field-from-report-table/m-p/742133#M240778</link>
      <description>&lt;P&gt;An event does contain the _time field (even if empty). You cannot remove it from the visualization. The only thing you can do is hide it by declaring it invisible with CSS.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2025 17:15:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-hide-time-field-from-report-table/m-p/742133#M240778</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-03-18T17:15:45Z</dc:date>
    </item>
  </channel>
</rss>

