The Results set of commands is used to manage the output of the search results. This set of commands can be used to filter the events, reformat the events, group them, reorder them, and read and write on the results.
The fields
command is used to keep (+
) or remove (-
) fields from the search results. If +
is used, then only the field list
followed by +
will be displayed, and if –
is used, then the field list
followed by –
will be removed from the current result set.
The syntax for the fields
command is as follows:
… | fields +/- field_list
Refer to the following example for better clarity:
index=_internal | top component cumulative_hits executes | fields – percent
In the preceding screenshot, we have used the top
command. The top
command returns the count and percentage of the specified fields. So, we have used fields – percent
, which shows all the fields, except percent. Similarly, the fields
command can be used to get the desired output.