Splunk Search

How can I hide '_time' field from report table?

wanda619
Path Finder
 
Labels (2)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

| fields - _time

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

| fields - _time

---
If this reply helps you, Karma would be appreciated.

lcguilfoil
Path Finder

Hi,

This removes the values of _time, but not the column header for me. Any ideas?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please share your query so we can see how you're creating the column header.  I suspect you need to remove "_time" from the table command.

---
If this reply helps you, Karma would be appreciated.
0 Karma

lcguilfoil
Path Finder

I'm using a Classic Dashboard. This is my XML:

<event>
	<search>
		<query>index=index 
		| fields - _time
		| table ApplicationName, ApplicationPath, LastRun</query>
	</search>
	<fields>ApplicationName, ApplicationPath, LastRun</fields>
	<option name="type">table</option>
</event>
0 Karma

richgalloway
SplunkTrust
SplunkTrust

I was able to eliminate the _time column by changing the event tag to a table tag.

      <table>
        <search>
          <query>index=_internal
		| fields - _time
		| table ApplicationName, ApplicationPath, LastRun</query>
          <earliest>$earliest$</earliest>
          <latest>$latest$</latest>
        </search>
        <option name="refresh.display">progressbar</option>
        <fields>["ApplicationName","ApplicationPath","LastRun"]</fields>
      </table>

 

---
If this reply helps you, Karma would be appreciated.
0 Karma

lcguilfoil
Path Finder

Hi, I'd like to keep it an event and not a table.

PickleRick
SplunkTrust
SplunkTrust

An event does contain the _time field (even if empty). You cannot remove it from the visualization. The only thing you can do is hide it by declaring it invisible with CSS.

Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...