In new search window (image attach) There are to column "Time" "Event"
How can I automatically(not write each time in query) edit the Time column that display another field like from event or add 1 more column ?
To achieve it by modifying ui-prefs.conf at user level OR app level.
splunkHome/etc/apps/myapp/local/ui-prefs.conf
OR
splunkHome/etc/users/USER/user-prefs/local/ui-prefs.conf
[default]
display.events.fields = ["event","anothefield"]