Nital
Nital

Reputation: 6114

How to remove a certain field from Splunk output

I am trying to remove a field from Search Result after running a command in Search Head on Splunk.

enter image description here

However as you can see in the following command that I am trying to run I see following error. I am quite new to Splunk and not sure what I need to do. Please guide.

enter image description here

Upvotes: 1

Views: 2993

Answers (1)

Akah
Akah

Reputation: 1920

I would suggest you to specify what you want as a result. The table command should help you :

xxxxxxxxxxxxxxxxxx |top DEPARTMENT | table DEPARTMENT,count

This way, you should only have the DEPARTMENT and count columns.

Upvotes: 3

Related Questions