Getting Data In

How do I hide a value from field in Splunk from list of two values?

AbhinavRanjan
Loves-to-Learn Lots

I have two values in a field source, I need to hide one i.e., http:kafka

AbhinavRanjan_0-1663508581919.png

 

Labels (1)
0 Karma

AbhinavRanjan
Loves-to-Learn Lots

@gcusello  query I am using

|table _time,cluster_name,namespaceName,podName,policyName,message, severity,action,tags,resource,source,

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @AbhinavRanjan,

how dinamic data source fields are generated?

is it possible for you to use a different name?

if not you have to manipulate your multivalue to always take the first or the second, something like this:

...
| eval source=mvindex(source,0)
| table _time,cluster_name,namespaceName,podName,policyName,message, severity,action,tags,resource,source,

Ciao.

Giuseppe

0 Karma

AbhinavRanjan
Loves-to-Learn Lots

@gcusello 

I have two source fields, One from the Splunk configuration(static throughout) and another from the logs which I am forwarding(dynamic data) , both are getting merged into a single field.

I just want to hide the configuration data, i.e http:kafka here from the source

AbhinavRanjan_1-1663518377501.png

 

 

0 Karma

AbhinavRanjan
Loves-to-Learn Lots

I have two source fields, One from the Splunk configuration(static throughout) and another from the logs which I am forwarding(dynamic data) , both are getting merged into a single field.

I just want to hide the configuration data, i.e http:kafka here from the source

AbhinavRanjan_0-1663518315049.png

 

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @AbhinavRanjan,

every event has one source value, so probably you're speaking of a search result aggregating more values from many events, probably in a stats command using the list option,

could you share your search?

Anyway, if you're speaking of a value from a stats command, use first or last or values instead of list option.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...