I have a log file date which is split on different fields ( date_hour, date_second, date_hour etc...)
Can i decide to only display : date_year,date_month, date_wday for example ?
Use the fields
or table
command to tell Splunk which fields to display. The fields
command is typically used within a query to reduce the number of fields being processed. The table
command is usually used at the end of a query to display results.
Hi,
sounds like the default datetime fields from splunk, why do you want to discard them?
These fields are exracted from _time
Because it's the only thing that change from a line to an other. So i don't need duplicate line in my table. I only one the message one time.