Knowledge Management

Results Table won't show tag AND its field

lisheridan
Explorer

I've tagged my host field with their respective customer. I want to display the host as well as the tagged value in a Results Table. Either host can be displayed or it's tag but not both.

This is what I am shooting for:

host customer data

host1 c1 123
host2 c1 345

Both fields show up in the Events Viewer and Events Table but not Results Table.

Tags (1)
0 Karma

lisheridan
Explorer

I figured it out. Syntax is:

top expanded_tb by tag::host,host

0 Karma
Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials

Welcome to the "Splunk Classroom Chronicles" series, created to help curious, career-minded learners get ...

Access Tokens Page - New & Improved

Splunk Observability Cloud recently launched an improved design for the access tokens page for better ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

🍂 Fall into November with a fresh lineup of Community Office Hours, Tech Talks, and Webinars we’ve ...