Splunk Search

How to create a report only showing values for 4 fields?

rmcole
New Member

Greetings, I'm trying to create a report that only shows 3 things in a search. I need to be able to not show everything else.
This is my search:

host=192.168.64.18 Group=* Username=* IP=* NOT "Session disconnected" NOT "Connection terminated for peer*"

I would prefer not having to do huge number of NOT statements to remove that extra fields.

Thanks

Tags (2)
0 Karma
1 Solution

strive
Influencer

Try this

Some search terms...| table host Group Username IP

Some search terms means: index=<your index name> earliest=<time that you need> latest=<time that you need>

and other search terms as per your need

View solution in original post

strive
Influencer

Try this

Some search terms...| table host Group Username IP

Some search terms means: index=<your index name> earliest=<time that you need> latest=<time that you need>

and other search terms as per your need

rmcole
New Member

yes plus the host. The idea for this report is for another group to run it and see who is connected via VPN

0 Karma

strive
Influencer

Do you need only Group, Username and IP as fields in your report?

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...