Splunk Search

Removing field from _raw field generated by collect for summary index

klim
Path Finder

I am using a scheduled report to save data to a summary index with the following query:

index=_internal | stats count by status  | collect index=test_index addtime=true testmode=true marker="sch_rpt_name=Test_Report" 

It outputs a _raw value like this :

01/12/2022 20:00:00 +0000, info_min_time=1642017600.000, info_max_time=1642106259.000, info_search_time=1642106259.959, count=63985, status=200, scheduled_report_test=Test_report

Is there a way to get rid of the info_search_time field?

Labels (1)
Tags (1)
0 Karma

tscroggins
Influencer

@klim 

The fields appear to be added by the summary index processor when the stash file is written to disk.

Is there a particular reason you do not want the data to appear in _raw?

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...