<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: no expected fields in sourcetype in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/no-expected-fields-in-sourcetype/m-p/401247#M4559</link>
    <description>&lt;P&gt;Thank you for your responce... but no... "All fields" - is already selected... (it seem my case is similar to the next &lt;A href="https://answers.splunk.com/answers/206812/splunk-add-on-for-cisco-wsa-not-extracting-fields.html"&gt;https://answers.splunk.com/answers/206812/splunk-add-on-for-cisco-wsa-not-extracting-fields.html&lt;/A&gt;)&lt;/P&gt;

&lt;P&gt;screenshot as an answer to your question is below:&lt;/P&gt;</description>
    <pubDate>Tue, 19 Feb 2019 10:28:26 GMT</pubDate>
    <dc:creator>infosec_kicb</dc:creator>
    <dc:date>2019-02-19T10:28:26Z</dc:date>
    <item>
      <title>no expected fields in sourcetype</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/no-expected-fields-in-sourcetype/m-p/401245#M4557</link>
      <description>&lt;P&gt;Hello all!&lt;BR /&gt;
resently i downloaded  Check Point App for Splunk. I configured in input.conf in order to force  all Chechpoint devices send their logs to sourcetype cp_log:&lt;BR /&gt;
        [udp://&lt;IP address="" of="" device=""&gt;:514]&lt;BR /&gt;
        sourcetype = cp_log&lt;BR /&gt;
now i can see all necesary  logs in this sourcetype, but if i look at soucetype settings - i can see that there should be many various fields. but i cannot see these fiedls while i perform search.  No necesary fields - no output on my   Check Point App for Splunk. how to get these fields? or should i extract every field mannually?&lt;/IP&gt;&lt;/P&gt;

&lt;P&gt;But search " sourcetype="cp_log" | table *"  returns  table with fields  that i need, but all of them are empty. Only field "Action" contain whole log text(look at attached picture)&lt;/P&gt;

&lt;P&gt;APP link - &lt;A href="https://splunkbase.splunk.com/app/4293/#/overview/" target="_blank"&gt;https://splunkbase.splunk.com/app/4293/#/overview/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:22:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/no-expected-fields-in-sourcetype/m-p/401245#M4557</guid>
      <dc:creator>infosec_kicb</dc:creator>
      <dc:date>2020-09-29T23:22:30Z</dc:date>
    </item>
    <item>
      <title>Re: no expected fields in sourcetype</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/no-expected-fields-in-sourcetype/m-p/401246#M4558</link>
      <description>&lt;P&gt;Hi @infosec_kicb ,&lt;BR /&gt;
I hope you have checked the "All fields" tab and put the coverage percent to "All Fields".&lt;BR /&gt;
Below is the attached snap for your reference.&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/6577iCD74E14C66BEFAE9/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 19 Feb 2019 10:12:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/no-expected-fields-in-sourcetype/m-p/401246#M4558</guid>
      <dc:creator>MoniM</dc:creator>
      <dc:date>2019-02-19T10:12:45Z</dc:date>
    </item>
    <item>
      <title>Re: no expected fields in sourcetype</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/no-expected-fields-in-sourcetype/m-p/401247#M4559</link>
      <description>&lt;P&gt;Thank you for your responce... but no... "All fields" - is already selected... (it seem my case is similar to the next &lt;A href="https://answers.splunk.com/answers/206812/splunk-add-on-for-cisco-wsa-not-extracting-fields.html"&gt;https://answers.splunk.com/answers/206812/splunk-add-on-for-cisco-wsa-not-extracting-fields.html&lt;/A&gt;)&lt;/P&gt;

&lt;P&gt;screenshot as an answer to your question is below:&lt;/P&gt;</description>
      <pubDate>Tue, 19 Feb 2019 10:28:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/no-expected-fields-in-sourcetype/m-p/401247#M4559</guid>
      <dc:creator>infosec_kicb</dc:creator>
      <dc:date>2019-02-19T10:28:26Z</dc:date>
    </item>
    <item>
      <title>Re: no expected fields in sourcetype</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/no-expected-fields-in-sourcetype/m-p/401248#M4560</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/6578i8A108831BF37CC13/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Feb 2019 10:29:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/no-expected-fields-in-sourcetype/m-p/401248#M4560</guid>
      <dc:creator>infosec_kicb</dc:creator>
      <dc:date>2019-02-19T10:29:10Z</dc:date>
    </item>
    <item>
      <title>Re: no expected fields in sourcetype</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/no-expected-fields-in-sourcetype/m-p/401249#M4561</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/6579iDC34EAA0EB5B265F/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;But search " sourcetype="cp_log" | table *" returns table with fields that i need, but all of them are empty. Only field "Action" contain whole log text(look at attached picture)&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 12:03:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/no-expected-fields-in-sourcetype/m-p/401249#M4561</guid>
      <dc:creator>infosec_kicb</dc:creator>
      <dc:date>2019-02-22T12:03:54Z</dc:date>
    </item>
  </channel>
</rss>

