Tabulating every field

Often, there are situations where we might want to present every event within the data in tabular format, without having to specify each field one by one. To do this, we simply use a wildcard (*) character as follows:

index=main sourcetype=access_combined | table * 

Get Splunk Operational Intelligence Cookbook - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.