Splunk Search

How can I define different export fields set of the "FieldPicker" for different apps?

William
Path Finder

For example, I want to only display "host", "sourcetype" for an app A in the default search result of "Events Table", but only "source", "eventtype" for app B. How can I do this?

0 Karma
1 Solution

William
Path Finder

the default fields set is defined by the viewstates.conf whose path is

$Splunk\etc\users\USER_NAME\APP_NAME\local\viewstates.conf

and it is controlled by the FieldPickers as follows

[flashtimeline:_current] FieldPicker_0_6_1.fields = ...

View solution in original post

William
Path Finder

yes. i have found the answer. thanks.

0 Karma

William
Path Finder

the default fields set is defined by the viewstates.conf whose path is

$Splunk\etc\users\USER_NAME\APP_NAME\local\viewstates.conf

and it is controlled by the FieldPickers as follows

[flashtimeline:_current] FieldPicker_0_6_1.fields = ...

jrodman
Splunk Employee
Splunk Employee

Are you talking about having a set of default selected fields by app?

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...