Splunk Search

Remove 'Select/Show in Results' from search results

I-Man
Communicator

I created a payload field that usually has about 8-20 lines of data. After the field was created, I clicked the field in the left hand section of the Search App and accidentally hit "Select/Show in results". Now I have a huge section of fields between each event due to the payload field containing so much data.

How do i remove this from showing in the search results? I looked everywhere and there does not seem to be an option to do this.

Thanks,
I-Man.

Tags (3)
0 Karma
1 Solution

Ayn
Legend
  1. Click "Pick fields" to the left in the Search app
  2. In the dialog that pops up, the list of fields that are shown in results are listed on the right-hand side under "Selected Fields". Remove those you don't want.

View solution in original post

0 Karma

Ayn
Legend
  1. Click "Pick fields" to the left in the Search app
  2. In the dialog that pops up, the list of fields that are shown in results are listed on the right-hand side under "Selected Fields". Remove those you don't want.
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...