Splunk Search

How can I visualize "table _raw" in the same format as the search result for the raw events in default Splunk search screen ?

Upas02
Path Finder

When I search for my events by giving index=myindex, I get my data in the proper format.
But when i try to print it out in a table, by using "index=myindex | table _raw" the formatting changes and I get the data in a different format.
How can get output of "table _raw" in the same way as events display in default search page.
Can it be done at query level or HTML or CSS level ?

Thanks in advance for your help.

0 Karma
1 Solution

CarsonZa
Contributor

you cant

"The table command is similar to the fields command in that it lets you specify the fields you want to keep in your results. Use table command when you want to retain data in tabular format."

http://docs.splunk.com/Documentation/Splunk/7.1.2/SearchReference/Table

the list display shows events collapsed, you might be missing key information. I don't see a good reason to print this display

View solution in original post

0 Karma

marycordova
SplunkTrust
SplunkTrust

can you post a screenshot of what you are trying to achieve as well as a sample log?

@marycordova
0 Karma

CarsonZa
Contributor

you cant

"The table command is similar to the fields command in that it lets you specify the fields you want to keep in your results. Use table command when you want to retain data in tabular format."

http://docs.splunk.com/Documentation/Splunk/7.1.2/SearchReference/Table

the list display shows events collapsed, you might be missing key information. I don't see a good reason to print this display

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...