Splunk Search

Which command is used to take away a field from the results display?

splunkerkanaka
New Member

Is there a specific command that we use to take away a field from the results displayed?

0 Karma

DalJeanis
Legend

There are two ways to do that, and they have different effects -

** FIELDS **

| fields - myfield
| fields + keepfield1 keepfield2 ... keepfieldX

The fields command is a distributable, streaming command. The first one removes myfield, the second one removes all fields except the listed ones, but also leaves the internal fields like _time. There is no limit on the number of records that can pass through the fields command.

** TABLE **

| table keepfield1 keepfield2 ... keepfieldX

The table command is NOT a streaming command, it is a transforming command. It keeps only the listed fields, deleting all internal fields that aren't listed, and formats the result as a table. WARNING - Table has a limit to the number of results it puts out.

0 Karma

niketn
Legend

@splunkerkanaka, it should be | fields - <YourFieldToBeRemoved>
Refer to documentation on fields command: http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Fields

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...