I've got a JSON event that I like to tabulate by using `index=myindex | table *`
When I do this though it includes some system fields, such as `host`, `index`, `linecount`, `punct`, `source`, `sourcetype`
Does anyone know if there's a way to exclude them without naming them all individually via a built in method/variable?
e.g. `index=myindex | fields - $SYSTEM_FIELDS$ | table *`
Thanks,
Henri
Not sure there is Splunk Variable available globally for that. But you can go with your approach by removing all default fields.
like,
| fields - _indextime, _cd, _bkt, host, index, linecount, punct, source, sourcetype, splunk_server, timestamp,date_*
_raw and _time also default field we should keep it. 🙂
Check below link for more details about Default Fields
https://docs.splunk.com/Documentation/Splunk/8.2.1/Knowledge/Usedefaultfields#Use_default_fields
Thanks
KV
▄︻̷̿┻̿═━一
If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.