Splunk Search

emit 3-column table from search (like CHART without aggregation)

Justin_Grant
Contributor

My search returns 10 fields in each event and I want to create a table with one row per event and columns for 3 of those fields. What's the right search command to use?

Essentially I want a slimmed-down version of the CHART command which doesn't do any aggregation but simply emits the fields I specify into a table.

I know I can manually, via clicking in the UI, elect to include the 3 fields in my results and then click the "events table" button to see a table, but I was looking for a search-language-only way to get this, ideally without having to see "_time" since I don't need it in my table.

0 Karma
1 Solution

ftk
Motivator

In 4.1:

sourcetype="syslog" | fields host, src, dst

Will display the three fields plus _time, so 4 fields total.

sourcetype="syslog" | table host, src, dst 

Will display only the three fields specified.

View solution in original post

ftk
Motivator

In 4.1:

sourcetype="syslog" | fields host, src, dst

Will display the three fields plus _time, so 4 fields total.

sourcetype="syslog" | table host, src, dst 

Will display only the three fields specified.

Justin_Grant
Contributor

@Ledion's answer below is accurate and solved my problem, but @ftk I'm accepting your answer because it includes useful details so I could understand why fields wasn't good enough, and that I need to be on 4.1 to use this command.

0 Karma

Ledion_Bitincka
Splunk Employee
Splunk Employee
.... | table column1, column2, column3

Justin_Grant
Contributor

I only wanted to see those specific fields. Per @ftk's answer above, fields also includes _time in the table. When you're not interested in time (as I wasn't in this case where I cared about the events but not when they showed up), table is better.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

And why does it need to exist? Or rather, what is the reason that both fields and table would both be needed?

0 Karma

hulahoop
Splunk Employee
Splunk Employee

is table a 4.1 command?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...