Splunk Search

How to delete fields name

shashi584
Explorer

I want to delete this field (VID) from one of my search query, this is not available under  Field extractions.

and what is the difference between (a and #) ?

shashi584_1-1633796036005.png

 

Labels (1)
0 Karma

shashi584
Explorer

I have extracted one field with the same name and I have deleted it, so I'm wondering why it's still displaying in the fields section. As you mentioned I have used the same field in search query hence it is showing which makes sence. 

Is there any way to remove/unhide completely from the field section without removing field data from the search query?

 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Ok, you lost me now 🙂

If you're using the field as part of your SPL search you need it processed, right? So you wouldn't want to remove the extraction because then you'd lose the ability to match on this field or calculate values based on it.

If you want simply to remove a field from being included in your search results, you can use the very surprisingly called 😉 command - fields

So add

 

| fields - yourfield yourotherfield ...

 

And the fields will be removed from the result set.

Of course the original event will still be visible unless you remove the _raw field.

Other than that - there is no possibility that I know of to keep the field in the result set and not show it in fields list. Remember that the fields list is populated automaticaly from the fields discovered during processing the search (see previous remarks about fast vs. verbose mode) which are presemt in sufficiently high percentage of results.

So if you had a field which would be set in just one of your 10k result events, it wouldn't show. But if half of your events contains a particular field, it will show up here.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

What do you mean by " this is not available under Field extractions"?

The field is being discovered either because it's used in the search or  you're using verbose mode.

The difference between a and # is that one is text field, the other is nummerical.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...