<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to display Event count when including only certain interesting fields criteria in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-display-Event-count-when-including-only-certain/m-p/750127#M119180</link>
    <description>&lt;P&gt;Hello, pardon my lack of proper vocab.&amp;nbsp; I hope I responded properly to your request for additional info. These are just the first two events from the data (.txt) file.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Thu Mar 31 2021 00:15:02 www1 sshd[4747]: Failed password for invalid user jabber from 118.142.68.222 port 3187 ssh2
Thu Mar 31 2021 00:15:02 www1 sshd[4111]: Failed password for invalid user db2 from 118.142.68.222 port 4150 ssh2
Thu Mar 31 2021 00:15:02 www1 sshd[5359]: Failed password for invalid user pmuser from 118.142.68.222 port 3356 ssh2
Thu Mar 31 2021 00:15:02 www1 su: pam_unix(su:session): session opened for user root by djohnson(uid=0)
Thu Mar 31 2021 00:15:02 www1 sshd[2660]: Failed password for invalid user irc from 118.142.68.222 port 4343 ssh2&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 19 Jul 2025 20:15:44 GMT</pubDate>
    <dc:creator>LS1</dc:creator>
    <dc:date>2025-07-19T20:15:44Z</dc:date>
    <item>
      <title>Unable to display Event count when including only certain interesting fields criteria</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-display-Event-count-when-including-only-certain/m-p/750108#M119173</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LS1_0-1752859704846.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/39692i4FCCD2027E46BD7B/image-size/large?v=v2&amp;amp;px=999" role="button" title="LS1_0-1752859704846.png" alt="LS1_0-1752859704846.png" /&gt;&lt;/span&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LS1_2-1752859759798.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/39694i8613740083613DE8/image-size/large?v=v2&amp;amp;px=999" role="button" title="LS1_2-1752859759798.png" alt="LS1_2-1752859759798.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello, maybe I don't have the vocabulary to find the answer when Googling.&amp;nbsp; I only submit this question after many attempts to find the answer on my own.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to figure out why neither "started" nor "blocked" will show events when I add them to my search criteria, as shown in the images. The "success" action returns events found in&amp;nbsp; the same "Interesting Fields" category ("action"). When using the search: index=security action="*" the event listings include what's been "blocked" (and what's been "started"). I can then add a search on "failed" password and the correct number of events display.&amp;nbsp; All of the "report" options: Top value, Events with this field, etc all display the proper count for "Blocked".&lt;/P&gt;&lt;P&gt;I have tried other "Interesting fields" with greater values wondering if there was some kind of limit set somewhere, but they work.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm sure it's simple but I cannot figure it out.&amp;nbsp; Please advise.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;LS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jul 2025 17:58:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-display-Event-count-when-including-only-certain/m-p/750108#M119173</guid>
      <dc:creator>LS1</dc:creator>
      <dc:date>2025-07-18T17:58:25Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to display Event count when including only certain interesting fields criteria</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-display-Event-count-when-including-only-certain/m-p/750114#M119174</link>
      <description>&lt;P&gt;It is a bit difficult to figure out what might be going on without some sample data. Please post some anonymised raw (unformatted) events in a code block using the &amp;lt;/&amp;gt; format button above so we can see what you are dealing with.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jul 2025 22:52:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-display-Event-count-when-including-only-certain/m-p/750114#M119174</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2025-07-18T22:52:42Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to display Event count when including only certain interesting fields criteria</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-display-Event-count-when-including-only-certain/m-p/750118#M119175</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/311696"&gt;@LS1&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;did you tried to click on the value in interesting fields to add to the search?&lt;/P&gt;&lt;P&gt;on this way, you can see the exact syntax to use that you can add to your main search.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sat, 19 Jul 2025 07:34:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-display-Event-count-when-including-only-certain/m-p/750118#M119175</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-07-19T07:34:25Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to display Event count when including only certain interesting fields criteria</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-display-Event-count-when-including-only-certain/m-p/750119#M119176</link>
      <description>&lt;P&gt;How did you come up with the second search? Is that the same as the first one just with one additional condition? What does your data look like?&lt;/P&gt;</description>
      <pubDate>Sat, 19 Jul 2025 07:46:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-display-Event-count-when-including-only-certain/m-p/750119#M119176</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-07-19T07:46:53Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to display Event count when including only certain interesting fields criteria</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-display-Event-count-when-including-only-certain/m-p/750124#M119177</link>
      <description>&lt;P&gt;Hello, pardon my lack of proper vocab.&amp;nbsp; For the second search, I opened the "action" field in "Interesting Fields" and then clicked on the desired query (blocked, started, and success). The only one that produces found events is success.&amp;nbsp; Below please find a sample of the practice data used:&lt;/P&gt;&lt;P&gt;Thu Mar 31 2021 00:15:02 www1 sshd[4747]: Failed password for invalid user jabber from 118.142.68.222 port 3187 ssh2&lt;BR /&gt;Thu Mar 31 2021 00:15:02 www1 sshd[4111]: Failed password for invalid user db2 from 118.142.68.222 port 4150 ssh2&lt;BR /&gt;Thu Mar 31 2021 00:15:02 www1 sshd[5359]: Failed password for invalid user pmuser from 118.142.68.222 port 3356 ssh2&lt;BR /&gt;Thu Mar 31 2021 00:15:02 www1 su: pam_unix(su:session): session opened for user root by djohnson(uid=0)&lt;BR /&gt;Thu Mar 31 2021 00:15:02 www1 sshd[2660]: Failed password for invalid user irc from 118.142.68.222 port 4343 ssh2&lt;BR /&gt;Thu Mar 31 2021 00:15:02 www1 sshd[1705]: Failed password for happy from 118.142.68.222 port 4174 ssh2&lt;BR /&gt;Thu Mar 31 2021 00:15:02 www1 sshd[1292]: Failed password for nobody from 118.142.68.222 port 1654 ssh2&lt;BR /&gt;Thu Mar 31 2021 00:15:02 www1 sshd[1560]: Failed password for invalid user local from 118.142.68.222 port 4616 ssh2&lt;BR /&gt;Thu Mar 31 2021 00:15:02 www1 sshd[59414]: Accepted password for myuan from 10.1.10.172 port 1569 ssh2&lt;BR /&gt;Thu Mar 31 2021 00:15:02 www1 sshd[1876]: Failed password for invalid user db2 from 118.142.68.222 port 1151 ssh2&lt;BR /&gt;Thu Mar 31 2021 00:15:02 www1 sshd[3310]: Failed password for apache from 118.142.68.222 port 4343 ssh2&lt;BR /&gt;Thu Mar 31 2021 00:15:02 www1 sshd[2149]: Failed password for nobody from 118.142.68.222 port 1527 ssh2&lt;BR /&gt;Thu Mar 31 2021 00:15:02 www1 sshd[2766]: Failed password for invalid user guest from 118.142.68.222 port 2581 ssh2&lt;BR /&gt;Thu Mar 31 2021 00:15:02 www1 sshd[3118]: pam_unix(sshd:session): session opened for user djohnson by (uid=0)&lt;/P&gt;</description>
      <pubDate>Sat, 19 Jul 2025 20:04:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-display-Event-count-when-including-only-certain/m-p/750124#M119177</guid>
      <dc:creator>LS1</dc:creator>
      <dc:date>2025-07-19T20:04:34Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to display Event count when including only certain interesting fields criteria</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-display-Event-count-when-including-only-certain/m-p/750125#M119178</link>
      <description>&lt;P&gt;Hello, pardon my lack of proper vocab.&amp;nbsp; For the second search, I opened the "action" field in "Interesting Fields" and then clicked on the desired query (blocked, started, and success). The only one that produces found events is success.&amp;nbsp; Below please find a sample of the practice data used:&lt;/P&gt;&lt;P&gt;Thu Mar 31 2021 00:15:02 www1 sshd[4747]: Failed password for invalid user jabber from 118.142.68.222 port 3187 ssh2&lt;BR /&gt;Thu Mar 31 2021 00:15:02 www1 sshd[4111]: Failed password for invalid user db2 from 118.142.68.222 port 4150 ssh2&lt;BR /&gt;Thu Mar 31 2021 00:15:02 www1 sshd[5359]: Failed password for invalid user pmuser from 118.142.68.222 port 3356 ssh2&lt;BR /&gt;Thu Mar 31 2021 00:15:02 www1 su: pam_unix(su:session): session opened for user root by djohnson(uid=0)&lt;BR /&gt;Thu Mar 31 2021 00:15:02 www1 sshd[2660]: Failed password for invalid user irc from 118.142.68.222 port 4343 ssh2&lt;BR /&gt;Thu Mar 31 2021 00:15:02 www1 sshd[1705]: Failed password for happy from 118.142.68.222 port 4174 ssh2&lt;BR /&gt;Thu Mar 31 2021 00:15:02 www1 sshd[1292]: Failed password for nobody from 118.142.68.222 port 1654 ssh2&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 19 Jul 2025 20:07:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-display-Event-count-when-including-only-certain/m-p/750125#M119178</guid>
      <dc:creator>LS1</dc:creator>
      <dc:date>2025-07-19T20:07:06Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to display Event count when including only certain interesting fields criteria</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-display-Event-count-when-including-only-certain/m-p/750126#M119179</link>
      <description>&lt;P&gt;Hello, pardon my lack of proper vocab.&amp;nbsp; Yes, for the second search I opened the "action" field in "Interesting Fields" and then clicked on the desired query (blocked, started, and success). The only one that produces found events is success.&amp;nbsp; Below please find a sample of the practice data used:&lt;/P&gt;&lt;P&gt;Thu Mar 31 2021 00:15:02 www1 sshd[4747]: Failed password for invalid user jabber from 118.142.68.222 port 3187 ssh2&lt;BR /&gt;Thu Mar 31 2021 00:15:02 www1 sshd[4111]: Failed password for invalid user db2 from 118.142.68.222 port 4150 ssh2&lt;BR /&gt;Thu Mar 31 2021 00:15:02 www1 sshd[5359]: Failed password for invalid user pmuser from 118.142.68.222 port 3356 ssh2&lt;/P&gt;</description>
      <pubDate>Sat, 19 Jul 2025 20:08:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-display-Event-count-when-including-only-certain/m-p/750126#M119179</guid>
      <dc:creator>LS1</dc:creator>
      <dc:date>2025-07-19T20:08:58Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to display Event count when including only certain interesting fields criteria</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-display-Event-count-when-including-only-certain/m-p/750127#M119180</link>
      <description>&lt;P&gt;Hello, pardon my lack of proper vocab.&amp;nbsp; I hope I responded properly to your request for additional info. These are just the first two events from the data (.txt) file.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Thu Mar 31 2021 00:15:02 www1 sshd[4747]: Failed password for invalid user jabber from 118.142.68.222 port 3187 ssh2
Thu Mar 31 2021 00:15:02 www1 sshd[4111]: Failed password for invalid user db2 from 118.142.68.222 port 4150 ssh2
Thu Mar 31 2021 00:15:02 www1 sshd[5359]: Failed password for invalid user pmuser from 118.142.68.222 port 3356 ssh2
Thu Mar 31 2021 00:15:02 www1 su: pam_unix(su:session): session opened for user root by djohnson(uid=0)
Thu Mar 31 2021 00:15:02 www1 sshd[2660]: Failed password for invalid user irc from 118.142.68.222 port 4343 ssh2&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 19 Jul 2025 20:15:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-display-Event-count-when-including-only-certain/m-p/750127#M119180</guid>
      <dc:creator>LS1</dc:creator>
      <dc:date>2025-07-19T20:15:44Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to display Event count when including only certain interesting fields criteria</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-display-Event-count-when-including-only-certain/m-p/750128#M119181</link>
      <description>&lt;P&gt;How is the action field populated as these events don't have "started", "blocked" nor "success"?&lt;/P&gt;</description>
      <pubDate>Sat, 19 Jul 2025 20:50:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-display-Event-count-when-including-only-certain/m-p/750128#M119181</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2025-07-19T20:50:52Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to display Event count when including only certain interesting fields criteria</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-display-Event-count-when-including-only-certain/m-p/750137#M119185</link>
      <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;pointed out, your events don't seem to contain the action field directly nor its values. They must be then populated by means of knowledge objects, most probably from TA_nix. Intuitively it smells like some kind of permission issues but I'm not 100% sure about that.&lt;/P&gt;</description>
      <pubDate>Sun, 20 Jul 2025 07:37:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-display-Event-count-when-including-only-certain/m-p/750137#M119185</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-07-20T07:37:35Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to display Event count when including only certain interesting fields criteria</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-display-Event-count-when-including-only-certain/m-p/750149#M119186</link>
      <description>&lt;P&gt;Hello GCusello, yes I clicked on the word(s) "Blocked" and "Started" in the "Action" field window.&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;When I use the query index=security action="*" all three actions: Blocked, Started and&amp;nbsp; Success appear as shown in my original question. If I click on "Success" all of my events are returned, when I click on the other two, my results are "No results found".&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I went down the list of Interesting Fields and tried all of the fields labeled with an&amp;nbsp;&lt;/SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LS1_0-1753017407156.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/39699i4B5637FF363B46A2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="LS1_0-1753017407156.png" alt="LS1_0-1753017407156.png" /&gt;&lt;/span&gt;&amp;nbsp;(not sure how to type that one) instead of an octothorp (#) and every one of them worked properly.&amp;nbsp; When I say I tried, I mean I opened the Interesting Fields and clicked on the desired selection, which alters the search criteria, the same way I have done with Blocked and Started.&amp;nbsp;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I do not know how the categories get created in the Interesting Fields but it appears there is something wrong with Blocked and Started.&lt;/P&gt;</description>
      <pubDate>Sun, 20 Jul 2025 13:27:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-display-Event-count-when-including-only-certain/m-p/750149#M119186</guid>
      <dc:creator>LS1</dc:creator>
      <dc:date>2025-07-20T13:27:24Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to display Event count when including only certain interesting fields criteria</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-display-Event-count-when-including-only-certain/m-p/750151#M119187</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/311696"&gt;@LS1&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;you should try something like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt; index=security action IN ("Blocked", "Started", "Success")&lt;/LI-CODE&gt;&lt;P&gt;I hinted to click on the value to be sure that the syntax is correct.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sun, 20 Jul 2025 14:25:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-display-Event-count-when-including-only-certain/m-p/750151#M119187</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-07-20T14:25:45Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to display Event count when including only certain interesting fields criteria</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-display-Event-count-when-including-only-certain/m-p/750173#M119190</link>
      <description>&lt;P&gt;Hello folks,&amp;nbsp; thanks for all of the feedback!!&amp;nbsp; When I tried the offered suggestion, I got results that included Started and Success, but I still didn't get results from Blocked.&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=security action IN ("Blocked", "Started", "Success") &lt;/LI-CODE&gt;&lt;P&gt;Splunk for Unix and Linux add-on will not load. I get an error stating the system it is trying to load does not run on either of the OS's.&amp;nbsp;&lt;/P&gt;&lt;P&gt;It makes sense that I don't have the proper Add-on loaded but I am unable to figure which it is. I appreciate all of your help, folks. I am trying to learn this tool and am in training. This is not a job related query. I do not want to waste your time. Thanks again!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 13:39:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-display-Event-count-when-including-only-certain/m-p/750173#M119190</guid>
      <dc:creator>LS1</dc:creator>
      <dc:date>2025-07-21T13:39:44Z</dc:date>
    </item>
  </channel>
</rss>

