Splunk Search

emit 3-column table from search (like CHART without aggregation)

Justin_Grant
Contributor

My search returns 10 fields in each event and I want to create a table with one row per event and columns for 3 of those fields. What's the right search command to use?

Essentially I want a slimmed-down version of the CHART command which doesn't do any aggregation but simply emits the fields I specify into a table.

I know I can manually, via clicking in the UI, elect to include the 3 fields in my results and then click the "events table" button to see a table, but I was looking for a search-language-only way to get this, ideally without having to see "_time" since I don't need it in my table.

0 Karma
1 Solution

ftk
Motivator

In 4.1:

sourcetype="syslog" | fields host, src, dst

Will display the three fields plus _time, so 4 fields total.

sourcetype="syslog" | table host, src, dst 

Will display only the three fields specified.

View solution in original post

ftk
Motivator

In 4.1:

sourcetype="syslog" | fields host, src, dst

Will display the three fields plus _time, so 4 fields total.

sourcetype="syslog" | table host, src, dst 

Will display only the three fields specified.

Justin_Grant
Contributor

@Ledion's answer below is accurate and solved my problem, but @ftk I'm accepting your answer because it includes useful details so I could understand why fields wasn't good enough, and that I need to be on 4.1 to use this command.

0 Karma

Ledion_Bitincka
Splunk Employee
Splunk Employee
.... | table column1, column2, column3

Justin_Grant
Contributor

I only wanted to see those specific fields. Per @ftk's answer above, fields also includes _time in the table. When you're not interested in time (as I wasn't in this case where I cared about the events but not when they showed up), table is better.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

And why does it need to exist? Or rather, what is the reason that both fields and table would both be needed?

0 Karma

hulahoop
Splunk Employee
Splunk Employee

is table a 4.1 command?

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...