I'd like the events displayed to have this data at the bottom as they do by default in the search app, but I can't find anything in the documentation about building it into a view.
someone please help, i'm using version 4.2 and the fields param doesn't seem to have any effect. In fact, it is instead displaying all fields. Is there some setting I am missing, or somewhere in a ViewStates config file which is overriding my defaults?
Hi Ciaran,
to view the medata fields with the EventViewer use the "fields" parameter. For instance:
<module name="EventsViewer">
<param name="fields">host source</param>
</module>
Document Reference
http://www.splunk.com/base/Documentation/4.1/Developer/ModuleReference#EventsViewer
NOTE: this answer is correct but is referring to how to do it when you are using the advanced XML. To do the same thing in the simplified XML you use
in the
Mick posted this here on our behalf.
What's the different answer? In this case we are using the Raw XML.
To restate the question (hopefully with more clarity) we're after a way to display the metadata for each event (i.e. host, source, sourcetype etc), just as it is displayed when you do a vanilla search. When using EventsViewer this isn't included by default. How do we get it there?
As posted by mzorzi, in the advanced XML you put
Worth noting is that there are in general two ways of setting fields for several modules.
1) setting a fields parameter in the module itself
2) Having an upstream FieldPicker or HiddenFieldPicker.
In cases where both conditions are present, the upstream setting always overrides the downstream setting.
This can be done if you edit the XML itself. Click Actions > Edit Dashboard this will open the dashboard editing popup. You'll see a link at the bottom left of the layer that says 'Edit name/XML'. Click that. You'll be taken to a page with a big textarea containing some XML. Find the element, which will look something like this:
<event>
<searchString>sourcetype=access_combined status=500</searchString>
<title>my dashboard test</title>
<earliestTime>-1h</earliestTime>
<latestTime></latestTime>
</event>
add a fifth node inside your element, making for a total of:
<event>
<searchString>sourcetype=access_combined status=500</searchString>
<title>my dashboard test</title>
<earliestTime>-1h</earliestTime>
<latestTime></latestTime>
<fields>host source url status bytes</fields>
</event>
NOTE: im making an assumption that you're talking about the dashboard UI builder, and the simplified XML. If you're using the advanced XML then you just find the EventsViewer
module in your view and you add an extra param right inside, like:
<param name="fields">host sourcetype clientip</param>