<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Fieldsummary returning entire log lines in resultset in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Fieldsummary-returning-entire-log-lines-in-resultset/m-p/61809#M7150</link>
    <description>&lt;P&gt;not sure if this is what the problem is, but are you explicitly setting the maxvals argument? it has a default value of 100 distinct values to return for each field if you don't set it explicitly. &lt;BR /&gt;
also, can you provide the search string you're using and a sample of the data that is working and a sample of what's not? &lt;BR /&gt;
also, what do you mean by running the query manually? it's a search command, so you can run it on the commandline if you have the necessary permissions.&lt;/P&gt;</description>
    <pubDate>Thu, 14 Mar 2013 22:23:53 GMT</pubDate>
    <dc:creator>piebob</dc:creator>
    <dc:date>2013-03-14T22:23:53Z</dc:date>
    <item>
      <title>Fieldsummary returning entire log lines in resultset</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Fieldsummary-returning-entire-log-lines-in-resultset/m-p/61808#M7149</link>
      <description>&lt;P&gt;We're using the fieldsummary function in splunk to return the list of fields (as it was designed) for each of our indexes.  This works great for almost all our indexes except for our windows snare index.  When fieldsummary is run on this index we get all the fields plus each individual log line being returned.&lt;/P&gt;

&lt;P&gt;Does anyone know how fieldsummary works and if the query can be run manually?  and/or if there's some sort of character limitation on fieldsummary that our windows event logs are tripping causing it spew all the log lines when the command is executed?&lt;/P&gt;

&lt;P&gt;e.g&lt;BR /&gt;
    index=snare | fieldsummary | table field&lt;/P&gt;

&lt;P&gt;field   &lt;BR /&gt;&lt;BR /&gt;
Account_Domain  &lt;BR /&gt;&lt;BR /&gt;
Account_For_Which_Logon_Failed  &lt;BR /&gt;&lt;BR /&gt;
Account_Name    &lt;BR /&gt;&lt;BR /&gt;
Account_Whose_Credentials_Were_Used &lt;BR /&gt;&lt;BR /&gt;
Additional_Information  &lt;BR /&gt;&lt;BR /&gt;
Authentication_Package  &lt;BR /&gt;&lt;BR /&gt;
Caller_Domain   &lt;BR /&gt;&lt;BR /&gt;
Caller_Logon_ID &lt;BR /&gt;&lt;BR /&gt;
Caller_Process_ID   &lt;BR /&gt;&lt;BR /&gt;
Caller_Process_Name &lt;BR /&gt;&lt;BR /&gt;
Caller_User_Name    &lt;BR /&gt;&lt;BR /&gt;
CategoryString  &lt;BR /&gt;&lt;BR /&gt;
Certificate_Information &lt;BR /&gt;&lt;BR /&gt;
Certificate_Issuer_Name &lt;BR /&gt;&lt;BR /&gt;
Certificate_Serial_Number   &lt;BR /&gt;&lt;BR /&gt;
Certificate_Thumbprint  &lt;BR /&gt;&lt;BR /&gt;
Client_Address  &lt;BR /&gt;&lt;BR /&gt;
Client_Port &lt;BR /&gt;&lt;BR /&gt;
ComputerName    &lt;BR /&gt;&lt;BR /&gt;
Creator_Process_ID  &lt;BR /&gt;&lt;BR /&gt;
Criticality &lt;BR /&gt;&lt;BR /&gt;
DataString  &lt;BR /&gt;&lt;BR /&gt;
Detailed_Authentication_Information &lt;BR /&gt;&lt;BR /&gt;
Domain  &lt;BR /&gt;&lt;BR /&gt;
EventCode   &lt;BR /&gt;&lt;BR /&gt;
EventLog    &lt;BR /&gt;&lt;BR /&gt;
EventLogType    &lt;BR /&gt;&lt;BR /&gt;
Event_Log   &lt;BR /&gt;&lt;BR /&gt;
ExpandedString  &lt;BR /&gt;&lt;BR /&gt;
Failure_Code    &lt;BR /&gt;&lt;BR /&gt;
Failure_Information &lt;BR /&gt;&lt;BR /&gt;
Failure_Reason  &lt;BR /&gt;&lt;BR /&gt;
Image_File_Name &lt;BR /&gt;&lt;BR /&gt;
Key_Length  &lt;BR /&gt;&lt;BR /&gt;
Logon_Account   &lt;BR /&gt;&lt;BR /&gt;
Logon_GUID  &lt;BR /&gt;&lt;BR /&gt;
Logon_ID    &lt;BR /&gt;&lt;BR /&gt;
Logon_Process   &lt;BR /&gt;&lt;BR /&gt;
Logon_Type  &lt;BR /&gt;&lt;BR /&gt;
Mar_11_20_08_03_10_200_12_14_YYY0029_xxxxx_xxxxx_com_MSWinEventLog_0_Security_200054_Mon_Mar_11_16_06_18_2013_4624_Microsoft_Windows_Security_Auditing_Ixxxxx_smith_N_A_Success_Audit_YYY0029_xxxxx_xxxxx_com_Logon__An_account_was_successfully_logged_on_____Subject   &lt;BR /&gt;&lt;BR /&gt;
Mar_11_20_08_03_10_200_12_14_YYY0029_xxxxx_xxxxx_com_MSWinEventLog_0_Security_200056_Mon_Mar_11_16_06_18_2013_4624_Microsoft_Windows_Security_Auditing_Ixxxxx_smith_N_A_Success_Audit_YYY0029_xxxxx_xxxxx_com_Logon__An_account_was_successfully_logged_on_____Subject   &lt;BR /&gt;&lt;BR /&gt;
Mar_11_20_08_03_10_200_70_45_YYY45_xxxxx_xxxxx_com_MSWinEventLog_0_Security_123596_Mon_Mar_11_16_06_06_2013_540_Security_somesrvacct_User_Success_Audit_YYY45_Logon_Logoff__Successful_Network_Logon    &lt;BR /&gt;&lt;BR /&gt;
Mar_11_20_08_03_10_200_70_45_YYY45_xxxxx_xxxxx_com_MSWinEventLog_0_Security_123597_Mon_Mar_11_16_06_06_2013_538_Security_somesrvacct_User_Success_Audit_YYY45_Logon_Logoff__User_Logoff  &lt;BR /&gt;&lt;BR /&gt;
Mar_11_20_08_03_10_200_70_45_YYY45_xxxxx_xxxxx_com_MSWinEventLog_0_Security_123598_Mon_Mar_11_16_06_06_2013_576_Security_somesrvacct_User_Success_Audit_YYY45_Logon_Logoff__Special_privileges_assigned_to_new_logon &lt;BR /&gt;&lt;BR /&gt;
Mar_11_20_08_03_10_200_70_45_YYY45_xxxxx_xxxxx_com_MSWinEventLog_0_Security_123599_Mon_Mar_11_16_06_06_2013_540_Security_somesrvacct_User_Success_Audit_YYY45_Logon_Logoff__Successful_Network_Logon    &lt;BR /&gt;&lt;BR /&gt;
Mar_11_20_08_03_10_200_70_45_YYY45_xxxxx_xxxxx_com_MSWinEventLog_0_Security_123600_Mon_Mar_11_16_06_06_2013_538_Security_somesrvacct_User_Success_Audit_YYY45_Logon_Logoff__User_Logoff  &lt;BR /&gt;&lt;BR /&gt;
Mar_11_20_08_03_10_200_86_180_YYY5686_xxxxx_xxxxx_com_MSWinEventLog_0_Security_2585_Mon_Mar_11_16_06_18_2013_4673_Microsoft_Windows_Security_Auditing_NT_AUTHORITY_LOCAL_SERVICE_N_A_Failure_Audit_YYY5686_xxxxx_xxxxx_com_Sensitive_Privilege_Use__A_privileged_service_was_called_____Subject   &lt;BR /&gt;&lt;BR /&gt;
Mar_11_20_08_03_10_202_105_17_YYY101155_xxxxx_xxxxx_com_MSWinEventLog_0_Security_230359_Mon_Mar_11_16_06_17_2013_4624_Microsoft_Windows_Security_Auditing_NT_AUTHORITY_ANONYMOUS_LOGON_N_A_Success_Audit_YYY101155_xxxxx_xxxxx_com_Logon__An_account_was_successfully_logged_on_____Subject    &lt;BR /&gt;&lt;BR /&gt;
Mar_11_20_08_03_10_202_105_17_YYY101155_xxxxx_xxxxx_com_MSWinEventLog_0_Security_230360_Mon_Mar_11_16_06_17_2013_4624_Microsoft_Windows_Security_Auditing_NT_AUTHORITY_ANONYMOUS_LOGON_N_A_Success_Audit_YYY101155_xxxxx_xxxxx_com_Logon__An_account_was_successfully_logged_on_____Subject    &lt;BR /&gt;&lt;BR /&gt;
.... &lt;BR /&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;whereas&lt;/STRONG&gt;&lt;BR /&gt;
    index=dns | fieldsummary | table field&lt;/P&gt;

&lt;P&gt;field   &lt;BR /&gt;&lt;BR /&gt;
Context &lt;BR /&gt;&lt;BR /&gt;
Direction   &lt;BR /&gt;&lt;BR /&gt;
InternalPktID   &lt;BR /&gt;&lt;BR /&gt;
Protocol    &lt;BR /&gt;&lt;BR /&gt;
Thread_ID   &lt;BR /&gt;&lt;BR /&gt;
date_hour   &lt;BR /&gt;&lt;BR /&gt;
date_mday   &lt;BR /&gt;&lt;BR /&gt;
date_minute &lt;BR /&gt;&lt;BR /&gt;
date_month  &lt;BR /&gt;&lt;BR /&gt;
date_second &lt;BR /&gt;&lt;BR /&gt;
date_wday   &lt;BR /&gt;&lt;BR /&gt;
date_year   &lt;BR /&gt;&lt;BR /&gt;
date_zone   &lt;BR /&gt;&lt;BR /&gt;
dest_domain &lt;BR /&gt;&lt;BR /&gt;
eventtype   &lt;BR /&gt;&lt;BR /&gt;
host    &lt;BR /&gt;&lt;BR /&gt;
index   &lt;BR /&gt;&lt;BR /&gt;
linecount   &lt;BR /&gt;&lt;BR /&gt;
product &lt;BR /&gt;&lt;BR /&gt;
punct   &lt;BR /&gt;&lt;BR /&gt;
source  &lt;BR /&gt;&lt;BR /&gt;
sourcetype  &lt;BR /&gt;&lt;BR /&gt;
splunk_server   &lt;BR /&gt;&lt;BR /&gt;
src_ip  &lt;BR /&gt;&lt;BR /&gt;
vendor  &lt;BR /&gt;&lt;BR /&gt;
xid &lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:31:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Fieldsummary-returning-entire-log-lines-in-resultset/m-p/61808#M7149</guid>
      <dc:creator>ltawfall</dc:creator>
      <dc:date>2020-09-28T13:31:11Z</dc:date>
    </item>
    <item>
      <title>Re: Fieldsummary returning entire log lines in resultset</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Fieldsummary-returning-entire-log-lines-in-resultset/m-p/61809#M7150</link>
      <description>&lt;P&gt;not sure if this is what the problem is, but are you explicitly setting the maxvals argument? it has a default value of 100 distinct values to return for each field if you don't set it explicitly. &lt;BR /&gt;
also, can you provide the search string you're using and a sample of the data that is working and a sample of what's not? &lt;BR /&gt;
also, what do you mean by running the query manually? it's a search command, so you can run it on the commandline if you have the necessary permissions.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2013 22:23:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Fieldsummary-returning-entire-log-lines-in-resultset/m-p/61809#M7150</guid>
      <dc:creator>piebob</dc:creator>
      <dc:date>2013-03-14T22:23:53Z</dc:date>
    </item>
    <item>
      <title>Re: Fieldsummary returning entire log lines in resultset</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Fieldsummary-returning-entire-log-lines-in-resultset/m-p/61810#M7151</link>
      <description>&lt;P&gt;It's not a maxval issue.  I'm just trying to get the field names, not the values in the fields.&lt;/P&gt;

&lt;P&gt;manually.. running the query  I mean generate the same data without using the "fieldsummary" command, some other method of generating the same data.&lt;/P&gt;

&lt;P&gt;All the lines.. that start with "Mar_11_20_08_03_10_202_" are gibberish.. not actual fields.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:31:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Fieldsummary-returning-entire-log-lines-in-resultset/m-p/61810#M7151</guid>
      <dc:creator>ltawfall</dc:creator>
      <dc:date>2020-09-28T13:31:17Z</dc:date>
    </item>
    <item>
      <title>Re: Fieldsummary returning entire log lines in resultset</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Fieldsummary-returning-entire-log-lines-in-resultset/m-p/61811#M7152</link>
      <description>&lt;P&gt;Did you try something like:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=snare |field - Mar_* | fieldsummary | table field
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Also, it may help to add a cluster command in the middle to reduce the load.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=snare |fields - Mar_* | cluster | fields - cluster_* | fieldsummary | table field
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 24 Nov 2014 16:01:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Fieldsummary-returning-entire-log-lines-in-resultset/m-p/61811#M7152</guid>
      <dc:creator>reed_kelly</dc:creator>
      <dc:date>2014-11-24T16:01:50Z</dc:date>
    </item>
  </channel>
</rss>

