I am new to splunk. Creating a report to count the successful and error logins to my system. The report shows the two columns but when I put the report on my dashboard, it adds two columns, span and span_days. I can't figure out how to remove those two extra columns. Any advice?
Use the fields command to specify the fields you want to display or those you want to remove.
| fields foo bar
| fields - span span_days
Ok - took a few tries but I got it to work with the field command. Thanks.
Use the fields command to specify the fields you want to display or those you want to remove.
| fields foo bar
| fields - span span_days