<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Defined field values showing no results, unless reloaded in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Defined-field-values-showing-no-results-unless-reloaded/m-p/405160#M71919</link>
    <description>&lt;P&gt;Thanks, but that has the same empty result. &lt;BR /&gt;
AU1 is one of many possible message Ids (and no, none of them works) that splunk shows me as available.&lt;/P&gt;

&lt;P&gt;cheers&lt;BR /&gt;
afx&lt;/P&gt;</description>
    <pubDate>Wed, 05 Jun 2019 14:37:56 GMT</pubDate>
    <dc:creator>afx</dc:creator>
    <dc:date>2019-06-05T14:37:56Z</dc:date>
    <item>
      <title>Defined field values showing no results, unless reloaded</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Defined-field-values-showing-no-results-unless-reloaded/m-p/405158#M71917</link>
      <description>&lt;P&gt;Hi, I have a totally weird situation.&lt;/P&gt;

&lt;P&gt;The field list on the left shows me the stuff I have defined.&lt;BR /&gt;
When I click on one of them, I see the field values. But when I then select one, the search does not show anything:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=amp_sal message_id=AU1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Delivers no results even though Splunk just told me there are AU1 message_ids...&lt;BR /&gt;
But when I exclude the field I see results:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=amp_sal message_id!=AU1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And I also see results when I perform a reload in the query:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=amp_sal 
| extract reload=t 
| search message_id=AU1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;So what is going on?&lt;BR /&gt;
Of course, there have been plenty of restarts.&lt;/P&gt;

&lt;P&gt;This is how the fields are defined:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;EXTRACT-sal = ^(?&amp;lt;message_id&amp;gt;.{3})(?&amp;lt;date&amp;gt;.{8})(?&amp;lt;time&amp;gt;.{6})(\w\w)(?&amp;lt;process_id&amp;gt;.{5})(?&amp;lt;task&amp;gt;.{5})(?&amp;lt;proctype&amp;gt;.{2})(?&amp;lt;term&amp;gt;.{8})(?&amp;lt;user&amp;gt;.{12})(?&amp;lt;transaction&amp;gt;.{20})(?&amp;lt;app&amp;gt;.{40})(?&amp;lt;client&amp;gt;.{3})(?&amp;lt;message&amp;gt;.{64})(?&amp;lt;src&amp;gt;.{20})
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And the best thing is, this is not consistent for the defined fields, some work ok, some exhibit the weird behavior.&lt;BR /&gt;
I tried to define them individually, but that did not change anything.&lt;/P&gt;

&lt;P&gt;Any ideas?&lt;BR /&gt;
thx&lt;BR /&gt;
afx&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2019 13:09:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Defined-field-values-showing-no-results-unless-reloaded/m-p/405158#M71917</guid>
      <dc:creator>afx</dc:creator>
      <dc:date>2019-06-05T13:09:40Z</dc:date>
    </item>
    <item>
      <title>Re: Defined field values showing no results, unless reloaded</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Defined-field-values-showing-no-results-unless-reloaded/m-p/405159#M71918</link>
      <description>&lt;P&gt;Hi @afx,&lt;/P&gt;

&lt;P&gt;does this work ? &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; index=amp_sal message_id="AU1"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Could be that AU1 is also a field name ? Is it the same regardless what you type for &lt;CODE&gt;message_id&lt;/CODE&gt; ?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2019 14:32:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Defined-field-values-showing-no-results-unless-reloaded/m-p/405159#M71918</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-06-05T14:32:59Z</dc:date>
    </item>
    <item>
      <title>Re: Defined field values showing no results, unless reloaded</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Defined-field-values-showing-no-results-unless-reloaded/m-p/405160#M71919</link>
      <description>&lt;P&gt;Thanks, but that has the same empty result. &lt;BR /&gt;
AU1 is one of many possible message Ids (and no, none of them works) that splunk shows me as available.&lt;/P&gt;

&lt;P&gt;cheers&lt;BR /&gt;
afx&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2019 14:37:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Defined-field-values-showing-no-results-unless-reloaded/m-p/405160#M71919</guid>
      <dc:creator>afx</dc:creator>
      <dc:date>2019-06-05T14:37:56Z</dc:date>
    </item>
  </channel>
</rss>

