I have aliased a field (let's call it
application_auth_id) to a new name (
user). I want my Splunk users to search using
user - not the old name,
application_auth_id shows up near the top of the interesting fields list, and it confuses the users.
How can I remove a field (
application_auth_id) from the fields sidebar?
As best I can tell, you can customize nothing about the Search app's look and feel in Splunk 6. 😞
In Splunk 5, custom versions of the flashtimeline and dashboard_live were pretty common.