Splunk Search

Can we decide to not show fields ?

magilbert1
Explorer

I have a log file date which is split on different fields ( date_hour, date_second, date_hour etc...)

Can i decide to only display : date_year,date_month, date_wday for example ?

Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Use the fields or table command to tell Splunk which fields to display. The fields command is typically used within a query to reduce the number of fields being processed. The table command is usually used at the end of a query to display results.

---
If this reply helps you, Karma would be appreciated.
0 Karma

dkeck
Influencer

Hi,

sounds like the default datetime fields from splunk, why do you want to discard them?

These fields are exracted from _time

0 Karma

magilbert1
Explorer

Because it's the only thing that change from a line to an other. So i don't need duplicate line in my table. I only one the message one time.

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...