Splunk ITSI

Finding the fields in itsi_event_management_group_index

keesling
Engager

I'm a newby to both splunk and itsi.  I think I can figure out how to find the fields in a lookup table and in an index, however, despite the name of this thing (itsi_event_management_group_index), it seems not to be an index as preceding it with "index=" yields no results, thus I can't figure out how to determine the names of the fields contained within it.  I've been provided with a query which references some of the fields via the 'stats' command, but... 1) How do I identify all such fields, and 2) what is this thing if not an index or lookup table?

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...