<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Select Fields at search time in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Select-Fields-at-search-time/m-p/10672#M538</link>
    <description>&lt;P&gt;Do you know that it is being extracted correctly?  Does the field/fields in your extraction return any results if you run:&lt;/P&gt;

&lt;P&gt;field_in_question=*&lt;/P&gt;

&lt;P&gt;If it does,  you can add &lt;CODE&gt;| fields list, your, fields, here&lt;/CODE&gt; to the end of a search.  Once you add a field by clicking the Show In Results in the Field Picker you will not need to use it any more.     &lt;/P&gt;</description>
    <pubDate>Tue, 30 Mar 2010 04:42:45 GMT</pubDate>
    <dc:creator>dskillman</dc:creator>
    <dc:date>2010-03-30T04:42:45Z</dc:date>
    <item>
      <title>Select Fields at search time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Select-Fields-at-search-time/m-p/10671#M537</link>
      <description>&lt;P&gt;I've got a field extraction defined in my props.conf, but now I want to be able to select it in a search without using the "Field Picker."  I've not found anything in the documentation yet that's been helpful.  Is there a way to do this that I'm missing?&lt;/P&gt;</description>
      <pubDate>Mon, 29 Mar 2010 23:43:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Select-Fields-at-search-time/m-p/10671#M537</guid>
      <dc:creator>thepocketwade</dc:creator>
      <dc:date>2010-03-29T23:43:06Z</dc:date>
    </item>
    <item>
      <title>Re: Select Fields at search time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Select-Fields-at-search-time/m-p/10672#M538</link>
      <description>&lt;P&gt;Do you know that it is being extracted correctly?  Does the field/fields in your extraction return any results if you run:&lt;/P&gt;

&lt;P&gt;field_in_question=*&lt;/P&gt;

&lt;P&gt;If it does,  you can add &lt;CODE&gt;| fields list, your, fields, here&lt;/CODE&gt; to the end of a search.  Once you add a field by clicking the Show In Results in the Field Picker you will not need to use it any more.     &lt;/P&gt;</description>
      <pubDate>Tue, 30 Mar 2010 04:42:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Select-Fields-at-search-time/m-p/10672#M538</guid>
      <dc:creator>dskillman</dc:creator>
      <dc:date>2010-03-30T04:42:45Z</dc:date>
    </item>
    <item>
      <title>Re: Select Fields at search time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Select-Fields-at-search-time/m-p/10673#M539</link>
      <description>&lt;P&gt;By "select" do you just mean to use it in a search, or do you mean to have it display under the raw event in the Event Viewer GUI? If the former, you don't need to do anything, you can just use the field. If the latter, then no. Unfortunately the Event Viewer UI is not as tightly linked to the search query (and use of &lt;CODE&gt;fields&lt;/CODE&gt;) as it could be.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Mar 2010 12:21:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Select-Fields-at-search-time/m-p/10673#M539</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-03-30T12:21:55Z</dc:date>
    </item>
    <item>
      <title>Re: Select Fields at search time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Select-Fields-at-search-time/m-p/10674#M540</link>
      <description>&lt;P&gt;yeah, but piping to fields leaves me with just the fields passed to the fields command.  I want to keep all the fields, but change what's "selected" and displayed below the log.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Mar 2010 19:42:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Select-Fields-at-search-time/m-p/10674#M540</guid>
      <dc:creator>thepocketwade</dc:creator>
      <dc:date>2010-03-30T19:42:56Z</dc:date>
    </item>
    <item>
      <title>Re: Select Fields at search time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Select-Fields-at-search-time/m-p/10675#M541</link>
      <description>&lt;P&gt;I mean the latter, might the link be tightened in future versions of Splunk?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Mar 2010 19:43:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Select-Fields-at-search-time/m-p/10675#M541</guid>
      <dc:creator>thepocketwade</dc:creator>
      <dc:date>2010-03-30T19:43:25Z</dc:date>
    </item>
    <item>
      <title>Re: Select Fields at search time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Select-Fields-at-search-time/m-p/10676#M542</link>
      <description>&lt;P&gt;Have you tried using the &lt;CODE&gt;charting&lt;/CODE&gt; view instead of the default &lt;CODE&gt;flashtimeline&lt;/CODE&gt; search view?This might give you what you are looking for.  I liked how you could temporarily change your shown fields using the &lt;CODE&gt;fields&lt;/CODE&gt; command in Splunk 3.x, but it didn't seem possible in Splunk 4, at least until I discovered this trick...&lt;/P&gt;

&lt;P&gt;You can get to the "Advanced Charting" view from the menu or tack by tacking "charting" to the URL path.&lt;/P&gt;

&lt;P&gt;Once your in the Advanced Charting view, you can minimize the Chart and formatting areas, and to focus on the results area.  Then you can tack on your &lt;CODE&gt;fields&lt;/CODE&gt; command to your search  (something like &lt;CODE&gt;| fields + field1 field2 ...&lt;/CODE&gt;).  And now you should only see your fields in the "Events Table" results.  So you can see only the fields you want, and in the order that you defined.  (Unfortunately, it doesn't work for the fields shown in the "Events List" results pane, which is a pain.)&lt;/P&gt;</description>
      <pubDate>Thu, 01 Apr 2010 22:08:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Select-Fields-at-search-time/m-p/10676#M542</guid>
      <dc:creator>Lowell</dc:creator>
      <dc:date>2010-04-01T22:08:21Z</dc:date>
    </item>
  </channel>
</rss>

