Splunk Search

How to create a report only showing values for 4 fields?

rmcole
New Member

Greetings, I'm trying to create a report that only shows 3 things in a search. I need to be able to not show everything else.
This is my search:

host=192.168.64.18 Group=* Username=* IP=* NOT "Session disconnected" NOT "Connection terminated for peer*"

I would prefer not having to do huge number of NOT statements to remove that extra fields.

Thanks

Tags (2)
0 Karma
1 Solution

strive
Influencer

Try this

Some search terms...| table host Group Username IP

Some search terms means: index=<your index name> earliest=<time that you need> latest=<time that you need>

and other search terms as per your need

View solution in original post

strive
Influencer

Try this

Some search terms...| table host Group Username IP

Some search terms means: index=<your index name> earliest=<time that you need> latest=<time that you need>

and other search terms as per your need

rmcole
New Member

yes plus the host. The idea for this report is for another group to run it and see who is connected via VPN

0 Karma

strive
Influencer

Do you need only Group, Username and IP as fields in your report?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...