<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Missing fields in the index in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Missing-fields-in-the-index/m-p/465278#M131083</link>
    <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;We have dynatrace data onboarded into Splunk though API. we came across this situation. When I ran the search with an index (index=abc)for last 4 hours/24 hours. There are only few fields are displaying in search results where if I ran the search for last 7 days  all fields are displaying. I selected All fields in the results too. There is no field limitation in limits.conf&lt;BR /&gt;
Can anyone please advise on this&lt;/P&gt;</description>
    <pubDate>Wed, 23 Oct 2019 17:25:16 GMT</pubDate>
    <dc:creator>iamsplunker31</dc:creator>
    <dc:date>2019-10-23T17:25:16Z</dc:date>
    <item>
      <title>Missing fields in the index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Missing-fields-in-the-index/m-p/465278#M131083</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;We have dynatrace data onboarded into Splunk though API. we came across this situation. When I ran the search with an index (index=abc)for last 4 hours/24 hours. There are only few fields are displaying in search results where if I ran the search for last 7 days  all fields are displaying. I selected All fields in the results too. There is no field limitation in limits.conf&lt;BR /&gt;
Can anyone please advise on this&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2019 17:25:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Missing-fields-in-the-index/m-p/465278#M131083</guid>
      <dc:creator>iamsplunker31</dc:creator>
      <dc:date>2019-10-23T17:25:16Z</dc:date>
    </item>
    <item>
      <title>Re: Missing fields in the index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Missing-fields-in-the-index/m-p/465279#M131084</link>
      <description>&lt;P&gt;Hi iamsplunker31&lt;BR /&gt;
at first a little question, did you executed your search using Verbose Mode or Smart Mode? try again using Verbose mode.&lt;/P&gt;

&lt;P&gt;Then remember that field extractions are related to sourcetype not to index, so check if the sourcetypes when you run your search on 7 days are the same in 4/24 hours.&lt;/P&gt;

&lt;P&gt;At least, remember that fields are showed only when they are present in results.&lt;BR /&gt;
In addition, if you have few occurrences of a field in search results, it's possible that field isn't displayed: you can force display putting the field between Selected Fields, in this way it's showed even if it has few values.&lt;/P&gt;

&lt;P&gt;Ciao.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2019 06:52:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Missing-fields-in-the-index/m-p/465279#M131084</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2019-10-24T06:52:39Z</dc:date>
    </item>
    <item>
      <title>Re: Missing fields in the index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Missing-fields-in-the-index/m-p/465280#M131085</link>
      <description>&lt;P&gt;Hi @gcusello , Thank you for your reply &lt;/P&gt;

&lt;P&gt;Yes, I'm running my search in Verbose mode only&lt;BR /&gt;
The sourcetype hasn't changed when I ran the search for last 7 days/ 24 hours  ,I displayed all fields with in the event.&lt;BR /&gt;
As you mentioned, The fields are may not be present in the results in selected time period(last 24hours)?&lt;BR /&gt;
Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2019 13:26:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Missing-fields-in-the-index/m-p/465280#M131085</guid>
      <dc:creator>iamsplunker31</dc:creator>
      <dc:date>2019-10-24T13:26:28Z</dc:date>
    </item>
    <item>
      <title>Re: Missing fields in the index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Missing-fields-in-the-index/m-p/465281#M131086</link>
      <description>&lt;P&gt;Hi iamsplunker31&lt;BR /&gt;
you're welcome!&lt;BR /&gt;
if this answer solves your problem, please accept and/or upvote it.&lt;BR /&gt;
Ciao and next time!&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2019 13:55:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Missing-fields-in-the-index/m-p/465281#M131086</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2019-10-24T13:55:41Z</dc:date>
    </item>
  </channel>
</rss>

