<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why does the search query does not show host, source, and sourcetype below each event? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-the-search-query-does-not-show-host-source-and/m-p/435358#M75967</link>
    <description>&lt;P&gt;Hi @neerajshah81,&lt;/P&gt;

&lt;P&gt;The default fields displayed with the event is decided by the user "Selected Fields"  which is normally shown on the left panel under "Selected fields" and on basis of the user selection - expanding the event and select the fields manually(selecting checkbox). Configuration setting is stored in &lt;CODE&gt;ui-prefs.conf&lt;/CODE&gt; of the user ie. &lt;CODE&gt;splunk\etc\users\"user_name"\search\local\ui-prefs.conf&lt;/CODE&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 11 Jul 2018 16:18:40 GMT</pubDate>
    <dc:creator>renjith_nair</dc:creator>
    <dc:date>2018-07-11T16:18:40Z</dc:date>
    <item>
      <title>Why does the search query does not show host, source, and sourcetype below each event?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-the-search-query-does-not-show-host-source-and/m-p/435356#M75965</link>
      <description>&lt;P&gt;Hi, I am taking Splunk Fundamentals course and during one of the lab exercises related to performing a search operation i noticed that my output of search query does not show the common fields like "host, source and source type"  below each event , which are normally supposed to be extracted by default.  My question is not about lab manual.  Basically, i am curious as in  What is making splunk to not show these 3 fields?   I am using the exact query that is listed in the manual.  Please refer to below screenshots.&lt;/P&gt;

&lt;P&gt;My output ( which doesn't show those 3 fields)&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5359i1413425F03008DB4/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Expected output as shown in the lab manual :  &lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5360iEA5373CE43B8C6D7/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jul 2018 15:49:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-the-search-query-does-not-show-host-source-and/m-p/435356#M75965</guid>
      <dc:creator>neerajshah81</dc:creator>
      <dc:date>2018-07-11T15:49:34Z</dc:date>
    </item>
    <item>
      <title>Re: Why does the search query does not show host, source, and sourcetype below each event?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-the-search-query-does-not-show-host-source-and/m-p/435357#M75966</link>
      <description>&lt;P&gt;The in-line callout of fields and values happens for &lt;CODE&gt;selected&lt;/CODE&gt; fields.  To select a field, click on the &lt;CODE&gt;All Fields&lt;/CODE&gt; link to get a field selector.  Click on the checkbox to the left of whichever fields you would like &lt;CODE&gt;Selected&lt;/CODE&gt;.  Then click the &lt;CODE&gt;Done&lt;/CODE&gt; button.  You will see a new &lt;CODE&gt;Selected Fields&lt;/CODE&gt; section above your existing &lt;CODE&gt;Interesting Fields&lt;/CODE&gt; section and your in-line callouts should be there, too.  These settings are somewhat sticky and I believe related to the neglected/no-longer-really-supported &lt;CODE&gt;viewstates&lt;/CODE&gt; feature of Splunk.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jul 2018 16:01:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-the-search-query-does-not-show-host-source-and/m-p/435357#M75966</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2018-07-11T16:01:22Z</dc:date>
    </item>
    <item>
      <title>Re: Why does the search query does not show host, source, and sourcetype below each event?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-the-search-query-does-not-show-host-source-and/m-p/435358#M75967</link>
      <description>&lt;P&gt;Hi @neerajshah81,&lt;/P&gt;

&lt;P&gt;The default fields displayed with the event is decided by the user "Selected Fields"  which is normally shown on the left panel under "Selected fields" and on basis of the user selection - expanding the event and select the fields manually(selecting checkbox). Configuration setting is stored in &lt;CODE&gt;ui-prefs.conf&lt;/CODE&gt; of the user ie. &lt;CODE&gt;splunk\etc\users\"user_name"\search\local\ui-prefs.conf&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jul 2018 16:18:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-the-search-query-does-not-show-host-source-and/m-p/435358#M75967</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2018-07-11T16:18:40Z</dc:date>
    </item>
    <item>
      <title>Re: Why does the search query does not show host, source, and sourcetype below each event?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-the-search-query-does-not-show-host-source-and/m-p/435359#M75968</link>
      <description>&lt;P&gt;Thank you woodcock &amp;amp; Renjith.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jul 2018 18:45:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-the-search-query-does-not-show-host-source-and/m-p/435359#M75968</guid>
      <dc:creator>neerajshah81</dc:creator>
      <dc:date>2018-07-11T18:45:04Z</dc:date>
    </item>
    <item>
      <title>Re: Why does the search query does not show host, source, and sourcetype below each event?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-the-search-query-does-not-show-host-source-and/m-p/435360#M75969</link>
      <description>&lt;P&gt;&lt;CODE&gt;Up-Votes&lt;/CODE&gt; appreciated.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jul 2018 21:58:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-the-search-query-does-not-show-host-source-and/m-p/435360#M75969</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2018-07-11T21:58:03Z</dc:date>
    </item>
    <item>
      <title>Re: Why does the search query does not show host, source, and sourcetype below each event?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-the-search-query-does-not-show-host-source-and/m-p/435361#M75970</link>
      <description>&lt;P&gt;Granted. Sorry getting used to splunk forums.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jul 2018 00:51:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-the-search-query-does-not-show-host-source-and/m-p/435361#M75970</guid>
      <dc:creator>neerajshah81</dc:creator>
      <dc:date>2018-07-12T00:51:51Z</dc:date>
    </item>
  </channel>
</rss>

