Splunk Search

How can I visualize "table _raw" in the same format as the search result for the raw events in default Splunk search screen ?

Upas02
Path Finder

When I search for my events by giving index=myindex, I get my data in the proper format.
But when i try to print it out in a table, by using "index=myindex | table _raw" the formatting changes and I get the data in a different format.
How can get output of "table _raw" in the same way as events display in default search page.
Can it be done at query level or HTML or CSS level ?

Thanks in advance for your help.

0 Karma
1 Solution

CarsonZa
Contributor

you cant

"The table command is similar to the fields command in that it lets you specify the fields you want to keep in your results. Use table command when you want to retain data in tabular format."

http://docs.splunk.com/Documentation/Splunk/7.1.2/SearchReference/Table

the list display shows events collapsed, you might be missing key information. I don't see a good reason to print this display

View solution in original post

0 Karma

marycordova
SplunkTrust
SplunkTrust

can you post a screenshot of what you are trying to achieve as well as a sample log?

@marycordova
0 Karma

CarsonZa
Contributor

you cant

"The table command is similar to the fields command in that it lets you specify the fields you want to keep in your results. Use table command when you want to retain data in tabular format."

http://docs.splunk.com/Documentation/Splunk/7.1.2/SearchReference/Table

the list display shows events collapsed, you might be missing key information. I don't see a good reason to print this display

0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...