Splunk Search

Search Line Filtering

Jared_Copeland
New Member

Hi I am new to splunk and hopefully this is a simple question to answer, i need to filter certain lines from the splunk event results here is an example of what i would like to do:

imagine a search result of 40 lines such as

category=7
computername=edas100
eventcode=624
eventtype=4
logfile=security

i only want to see information on eventcode and eventtype and the other information is not important to me

how can i format my search or how can i format the data after to hide all other fields except the ones i want to see (eventcode and eventtype for this example)

thanks very much for any help!

Tags (3)
0 Karma

southeringtonp
Motivator

If you want to do it interactively, use the field picker to pull out the fields you want, and click on the 'Events Viewer' square icon (the middle one) above the search results.

If you want it as a fixed part of the search try using fields or particularly table:

| table eventcode, eventtype
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mile High Learning with Splunk University, Denver, Colorado

If Denver is known for its mile-high elevation, Splunk University is about to raise the bar on technical ...

IT Service Intelligence 5.0 Series: Your Guide to the June Launch

We are excited to announce the June release of Splunk IT Service Intelligence (ITSI) 5.0. This update ...

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...