<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Missing starting characters in a field in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Missing-starting-characters-in-a-field/m-p/438544#M124816</link>
    <description>&lt;P&gt;What is the actual DB query? Any props/transforms applied to extract fields?&lt;/P&gt;</description>
    <pubDate>Wed, 06 Jun 2018 08:08:33 GMT</pubDate>
    <dc:creator>FrankVl</dc:creator>
    <dc:date>2018-06-06T08:08:33Z</dc:date>
    <item>
      <title>Missing starting characters in a field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Missing-starting-characters-in-a-field/m-p/438541#M124813</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;

&lt;P&gt;I am facing a strange issue like missing 2 starting characters in a field.My data is coming as a view from datawarehouse and its a a sql server .I am getting proper name in warehouse but not in splunk dashboard or search.Iam creating index using splunk db connect using the view .&lt;/P&gt;

&lt;P&gt;I have "Name" field which has a value like "LL3CCCZM2" in warehouse , But is showing as 3CCCZM2 in splunk dashboard.&lt;/P&gt;

&lt;P&gt;Can  anyone help me to find the reason and rectify this in splunk please .&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jun 2018 07:25:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Missing-starting-characters-in-a-field/m-p/438541#M124813</guid>
      <dc:creator>umsundar2015</dc:creator>
      <dc:date>2018-06-06T07:25:18Z</dc:date>
    </item>
    <item>
      <title>Re: Missing starting characters in a field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Missing-starting-characters-in-a-field/m-p/438542#M124814</link>
      <description>&lt;P&gt;Please provide the configuration you use to collect and parse the data and the search you are running that gives the broken results. Some screenshots would also be helpful (make sure to mask any sensitive data where needed).&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jun 2018 07:49:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Missing-starting-characters-in-a-field/m-p/438542#M124814</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-06-06T07:49:26Z</dc:date>
    </item>
    <item>
      <title>Re: Missing starting characters in a field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Missing-starting-characters-in-a-field/m-p/438543#M124815</link>
      <description>&lt;P&gt;DB connect Config as below :&lt;BR /&gt;
Input Type:Batch Input&lt;BR /&gt;
Max Rows to Retrieve :10000000&lt;/P&gt;

&lt;P&gt;Fetch Size :default&lt;BR /&gt;
The number of rows to return at a time from the database. Default is 300.&lt;BR /&gt;
Timestamp&lt;BR /&gt;
Current Index Time&lt;/P&gt;

&lt;P&gt;Output Timestamp Format:yyyy-MM-dd HH:mm:ss&lt;BR /&gt;
Execution Frequency:45 01 * * *&lt;/P&gt;

&lt;P&gt;search :&lt;BR /&gt;
index=DNS| fillnull value=others|search factor="&lt;EM&gt;" Group="&lt;/EM&gt;" os="*"|search Status="Not Reporting"|Table  Identifier,factor, Tag, hardware,Company, os,Group&lt;/P&gt;

&lt;P&gt;Please help me to find the issue &lt;/P&gt;</description>
      <pubDate>Wed, 06 Jun 2018 08:03:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Missing-starting-characters-in-a-field/m-p/438543#M124815</guid>
      <dc:creator>umsundar2015</dc:creator>
      <dc:date>2018-06-06T08:03:04Z</dc:date>
    </item>
    <item>
      <title>Re: Missing starting characters in a field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Missing-starting-characters-in-a-field/m-p/438544#M124816</link>
      <description>&lt;P&gt;What is the actual DB query? Any props/transforms applied to extract fields?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jun 2018 08:08:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Missing-starting-characters-in-a-field/m-p/438544#M124816</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-06-06T08:08:33Z</dc:date>
    </item>
    <item>
      <title>Re: Missing starting characters in a field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Missing-starting-characters-in-a-field/m-p/438545#M124817</link>
      <description>&lt;P&gt;It is actually a sql query with which the view is created .Nothing is set in props and transform etc .&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jun 2018 09:12:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Missing-starting-characters-in-a-field/m-p/438545#M124817</guid>
      <dc:creator>umsundar2015</dc:creator>
      <dc:date>2018-06-06T09:12:28Z</dc:date>
    </item>
  </channel>
</rss>

