For example, I want to only display "host", "sourcetype" for an app A in the default search result of "Events Table", but only "source", "eventtype" for app B. How can I do this?
the default fields set is defined by the viewstates.conf whose path is
$Splunk\etc\users\USER_NAME\APP_NAME\local\viewstates.conf
and it is controlled by the FieldPickers as follows
[flashtimeline:_current] FieldPicker_0_6_1.fields = ...
yes. i have found the answer. thanks.
the default fields set is defined by the viewstates.conf whose path is
$Splunk\etc\users\USER_NAME\APP_NAME\local\viewstates.conf
and it is controlled by the FieldPickers as follows
[flashtimeline:_current] FieldPicker_0_6_1.fields = ...
Are you talking about having a set of default selected fields by app?