I have aliased a field (let's call it application_auth_id
) to a new name (user
). I want my Splunk users to search using user
- not the old name, application_auth_id
. Unfortunately, application_auth_id
shows up near the top of the interesting fields list, and it confuses the users.
How can I remove a field (application_auth_id
) from the fields sidebar?
As best I can tell, you can customize nothing about the Search app's look and feel in Splunk 6. 😞
In Splunk 5, custom versions of the flashtimeline and dashboard_live were pretty common.
Is this along the lines of what you are looking for?
http://answers.splunk.com/answers/110886/hide-interesting-fields
Doesn't work in Splunk 6
probably worked in Splunk 5...
Thanks!
Thanks - I had searched for this, but didn't find it! I will try this and see if it works!