I have two values in a field source, I need to hide one i.e., http:kafka
@gcusello query I am using
|table _time,cluster_name,namespaceName,podName,policyName,message, severity,action,tags,resource,source,
Hi @AbhinavRanjan,
how dinamic data source fields are generated?
is it possible for you to use a different name?
if not you have to manipulate your multivalue to always take the first or the second, something like this:
...
| eval source=mvindex(source,0)
| table _time,cluster_name,namespaceName,podName,policyName,message, severity,action,tags,resource,source,
Ciao.
Giuseppe
I have two source fields, One from the Splunk configuration(static throughout) and another from the logs which I am forwarding(dynamic data) , both are getting merged into a single field.
I just want to hide the configuration data, i.e http:kafka here from the source
I have two source fields, One from the Splunk configuration(static throughout) and another from the logs which I am forwarding(dynamic data) , both are getting merged into a single field.
I just want to hide the configuration data, i.e http:kafka here from the source
Hi @AbhinavRanjan,
every event has one source value, so probably you're speaking of a search result aggregating more values from many events, probably in a stats command using the list option,
could you share your search?
Anyway, if you're speaking of a value from a stats command, use first or last or values instead of list option.
Ciao.
Giuseppe