Splunk Search

How to create a report only showing values for 4 fields?

rmcole
New Member

Greetings, I'm trying to create a report that only shows 3 things in a search. I need to be able to not show everything else.
This is my search:

host=192.168.64.18 Group=* Username=* IP=* NOT "Session disconnected" NOT "Connection terminated for peer*"

I would prefer not having to do huge number of NOT statements to remove that extra fields.

Thanks

Tags (2)
0 Karma
1 Solution

strive
Influencer

Try this

Some search terms...| table host Group Username IP

Some search terms means: index=<your index name> earliest=<time that you need> latest=<time that you need>

and other search terms as per your need

View solution in original post

strive
Influencer

Try this

Some search terms...| table host Group Username IP

Some search terms means: index=<your index name> earliest=<time that you need> latest=<time that you need>

and other search terms as per your need

rmcole
New Member

yes plus the host. The idea for this report is for another group to run it and see who is connected via VPN

0 Karma

strive
Influencer

Do you need only Group, Username and IP as fields in your report?

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...