Splunk Operational Intelligence Cookbook
上QQ阅读APP看书,第一时间看更新

Tabulating every field

Often, there are situations where we might want to present every event within the data in tabular format, without having to specify each field one by one. To do this, we simply use a wildcard (*) character as follows:

index=main sourcetype=access_combined | table *