Table/fields
Splunk can display the fields contained in each event in table format by piping the events to the table command along with a list of the fields to display, in the order in which they are to be arranged from left to right. The resultant table will contain one row per event and a column for each specified field. Splunk will automatically switch to the Statistics tab to display the resulting table.
Displaying a table of all of the fields in an event is not usually desirable; you can use the table command to specify the fields that the table is to include, and to specify the order in which the fields are displayed. The following examples show how to use the table command; the first example includes using an asterisk to create a table ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access