Splunk Search

How to create a report only showing values for 4 fields?

rmcole
New Member

Greetings, I'm trying to create a report that only shows 3 things in a search. I need to be able to not show everything else.
This is my search:

host=192.168.64.18 Group=* Username=* IP=* NOT "Session disconnected" NOT "Connection terminated for peer*"

I would prefer not having to do huge number of NOT statements to remove that extra fields.

Thanks

Tags (2)
0 Karma
1 Solution

strive
Influencer

Try this

Some search terms...| table host Group Username IP

Some search terms means: index=<your index name> earliest=<time that you need> latest=<time that you need>

and other search terms as per your need

View solution in original post

strive
Influencer

Try this

Some search terms...| table host Group Username IP

Some search terms means: index=<your index name> earliest=<time that you need> latest=<time that you need>

and other search terms as per your need

rmcole
New Member

yes plus the host. The idea for this report is for another group to run it and see who is connected via VPN

0 Karma

strive
Influencer

Do you need only Group, Username and IP as fields in your report?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...