This question was asked before, but not really answered. I have a search that returns columns dynamically created so I don't know the specific column/field names to include, but I do know the columns/fields that I need to remove so the graph will total and display properly. Is there a way to remove those columns?
 
					
				
		
Are you looking for fields command?
Remove the "host" and "ip" fields.
... | fields - host, ip
More information in this link
http://docs.splunk.com/Documentation/Splunk/6.1.3/SearchReference/Fields
Table Name:TempDay
Filed Name: AttendanceDate
Code:
Dim curDatabase As DAO.Database
 Dim tblPersons As DAO.TableDef
    Set curDatabase = CurrentDb
    Set TempDay = curDatabase.TableDefs("TempDay")
     DoCmd.RunSQL "ALTER TABLE TempDay DROP COLUMN AttendanceDate"
‘For deleting more than one column try below
  DoCmd.RunSQL "ALTER TABLE TempDay DROP COLUMN  Second Column Name"
  DoCmd.RunSQL "ALTER TABLE TempDay DROP COLUMN  Third Column Name"
the question is not that clear but you can always use |fields -col1,col2 to remove the column. There is no harm if they don't exist as well..
 
					
				
		
Are you looking for fields command?
Remove the "host" and "ip" fields.
... | fields - host, ip
More information in this link
http://docs.splunk.com/Documentation/Splunk/6.1.3/SearchReference/Fields
 
					
				
		
very useful - thank you
 
					
				
		
You're welcome 🙂
thanks! I didn't realize fields had a "-" option!
