fields command syntax details
The required syntax is in bold.
- fields [+|-] <field-list>
- Syntax: <field>, <field>, ...
- Description: Comma-delimited list of fields to keep or remove. You can use a wild card character in the field names, but must enclose those field names in single quotation marks. For example
... | fields host, 'server*'
- + | -
- Syntax: + | -
- Description: If the plus ( + ) symbol is specified, only the fields in the
field-listare kept in the results. If the negative ( - ) symbol is specified, the fields in the
field-listare removed from the results. The symbol you specify applies to all of the fields in the
- Default: +
fields command overview
fields command usage
This documentation applies to the following versions of Splunk® Cloud Services: current