- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
For example, I want to only display "host", "sourcetype" for an app A in the default search result of "Events Table", but only "source", "eventtype" for app B. How can I do this?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
the default fields set is defined by the viewstates.conf whose path is
$Splunk\etc\users\USER_NAME\APP_NAME\local\viewstates.conf
and it is controlled by the FieldPickers as follows
[flashtimeline:_current] FieldPicker_0_6_1.fields = ...
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
yes. i have found the answer. thanks.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
the default fields set is defined by the viewstates.conf whose path is
$Splunk\etc\users\USER_NAME\APP_NAME\local\viewstates.conf
and it is controlled by the FieldPickers as follows
[flashtimeline:_current] FieldPicker_0_6_1.fields = ...
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
![jrodman jrodman](https://community.splunk.com/legacyfs/online/avatars/35.jpg)
![Splunk Employee Splunk Employee](/html/@F88B7774A2BF2E9108D79A067A92A581/rank_icons/employee-16.png)
Are you talking about having a set of default selected fields by app?
![](/skins/images/89D5ADE867CBAF0B5A525B7E23D83D7E/responsive_peak/images/icon_anonymous_message.png)