Splunk Search

How can I hide '_time' field from report table?

wanda619
Path Finder
 
Labels (2)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

| fields - _time

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

| fields - _time

---
If this reply helps you, Karma would be appreciated.

lcguilfoil
Path Finder

Hi,

This removes the values of _time, but not the column header for me. Any ideas?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please share your query so we can see how you're creating the column header.  I suspect you need to remove "_time" from the table command.

---
If this reply helps you, Karma would be appreciated.
0 Karma

lcguilfoil
Path Finder

I'm using a Classic Dashboard. This is my XML:

<event>
	<search>
		<query>index=index 
		| fields - _time
		| table ApplicationName, ApplicationPath, LastRun</query>
	</search>
	<fields>ApplicationName, ApplicationPath, LastRun</fields>
	<option name="type">table</option>
</event>
0 Karma

richgalloway
SplunkTrust
SplunkTrust

I was able to eliminate the _time column by changing the event tag to a table tag.

      <table>
        <search>
          <query>index=_internal
		| fields - _time
		| table ApplicationName, ApplicationPath, LastRun</query>
          <earliest>$earliest$</earliest>
          <latest>$latest$</latest>
        </search>
        <option name="refresh.display">progressbar</option>
        <fields>["ApplicationName","ApplicationPath","LastRun"]</fields>
      </table>

 

---
If this reply helps you, Karma would be appreciated.
0 Karma

lcguilfoil
Path Finder

Hi, I'd like to keep it an event and not a table.

PickleRick
SplunkTrust
SplunkTrust

An event does contain the _time field (even if empty). You cannot remove it from the visualization. The only thing you can do is hide it by declaring it invisible with CSS.

Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...