Splunk Search

Is there a shortcut to piping the table command where splunk-created fields are automatically excluded?

morethanyell
Builder

Given that my search criteria is this: index=some_index sourcetype=some_sourcetype, is there a shortcut to piping the | table * command where splunk-created fields are automatically excluded? (Basically wanted to do this: | fields - _raw, _time, eventtype, host, index, sourcetype, source, linecount, splunk_server, splunk_server_group, timestamp, punct in the shortest possible way.

0 Karma
1 Solution

niketn
Legend

@morethanyell, you can create a macro for excluding Splunk's default fields and use that macro in your searches. for example your macro code can be | fields - _* date_* .....

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

View solution in original post

0 Karma

niketn
Legend

@morethanyell, you can create a macro for excluding Splunk's default fields and use that macro in your searches. for example your macro code can be | fields - _* date_* .....

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

morethanyell
Builder

@niketnilay The noob in me is slapping me. Thank you. I did not think of that.

0 Karma

niketn
Legend

@morethanyell there is always first time for everything 🙂 Now you know.

I have converted my comment to answer. Please accept to mark this question as answered!

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...