Splunk Search

emit 3-column table from search (like CHART without aggregation)

Justin_Grant
Contributor

My search returns 10 fields in each event and I want to create a table with one row per event and columns for 3 of those fields. What's the right search command to use?

Essentially I want a slimmed-down version of the CHART command which doesn't do any aggregation but simply emits the fields I specify into a table.

I know I can manually, via clicking in the UI, elect to include the 3 fields in my results and then click the "events table" button to see a table, but I was looking for a search-language-only way to get this, ideally without having to see "_time" since I don't need it in my table.

0 Karma
1 Solution

ftk
Motivator

In 4.1:

sourcetype="syslog" | fields host, src, dst

Will display the three fields plus _time, so 4 fields total.

sourcetype="syslog" | table host, src, dst 

Will display only the three fields specified.

View solution in original post

ftk
Motivator

In 4.1:

sourcetype="syslog" | fields host, src, dst

Will display the three fields plus _time, so 4 fields total.

sourcetype="syslog" | table host, src, dst 

Will display only the three fields specified.

Justin_Grant
Contributor

@Ledion's answer below is accurate and solved my problem, but @ftk I'm accepting your answer because it includes useful details so I could understand why fields wasn't good enough, and that I need to be on 4.1 to use this command.

0 Karma

Ledion_Bitincka
Splunk Employee
Splunk Employee
.... | table column1, column2, column3

Justin_Grant
Contributor

I only wanted to see those specific fields. Per @ftk's answer above, fields also includes _time in the table. When you're not interested in time (as I wasn't in this case where I cared about the events but not when they showed up), table is better.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

And why does it need to exist? Or rather, what is the reason that both fields and table would both be needed?

0 Karma

hulahoop
Splunk Employee
Splunk Employee

is table a 4.1 command?

0 Karma
Get Updates on the Splunk Community!

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...

Splunk New Course Releases for a Changing World

Every day, the world feels like it’s moving faster with new technological breakthroughs, AI innovation, and ...

Insights from .conf 2025, Smart Edge Processor Scaling, and a New Splunk Lantern ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...