<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Search event is not providing output for fields in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Search-event-is-not-providing-output-for-fields/m-p/518424#M145786</link>
    <description>&lt;P&gt;Adding screenshots for events created and search result. Fields are extracted but result is not listed.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="event_collector data.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10712iDC3F370EBA489510/image-size/large?v=v2&amp;amp;px=999" role="button" title="event_collector data.PNG" alt="event_collector data.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="extracted_fields Urgency.PNG" style="width: 918px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10710i08EE3FFA72575B07/image-size/large?v=v2&amp;amp;px=999" role="button" title="extracted_fields Urgency.PNG" alt="extracted_fields Urgency.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Search_using Urgency.PNG" style="width: 875px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10711i1F56F99046473188/image-size/large?v=v2&amp;amp;px=999" role="button" title="Search_using Urgency.PNG" alt="Search_using Urgency.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 08 Sep 2020 11:26:51 GMT</pubDate>
    <dc:creator>pallavi_prabhu_</dc:creator>
    <dc:date>2020-09-08T11:26:51Z</dc:date>
    <item>
      <title>Search event is not providing output for fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-event-is-not-providing-output-for-fields/m-p/518395#M145779</link>
      <description>&lt;P&gt;We have created http event with below command:&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;A title="http://localhost:8088/services/collector" href="http://localhost:8088/services/collector" target="_blank" rel="noreferrer noopener"&gt;http://localhost:8088/services/collector&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt;Body:&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;{ &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"sourcetype":"trial", &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"event":"ITSM1", &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"fields": &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;{ &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"discription":"ITSM1 inserting data", &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"urgency":"High" &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;} }&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;This data is visible on splunk enterprise. Now we are trying to search this event using criteria as Urgency = High . but it didn't return any event.&lt;/P&gt;&lt;P&gt;We tried using curl command still same result.&amp;nbsp; Can you suggest what could be the issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;C:\Users\terminal&amp;gt;curl -k -u username:Password&amp;nbsp;&lt;A href="https://localhost:8089/services/search/jobs" target="_blank" rel="noopener"&gt;https://localhost:8089/services/search/jobs&lt;/A&gt; -d output_mode="json" -d search="search index=main urgency=high"&lt;/P&gt;&lt;P&gt;{"sid":"1599554403.2242"}&lt;/P&gt;&lt;P&gt;C::\Users\terminal&amp;gt;curl -k -u username:Password&amp;nbsp;:username:Password&amp;nbsp; &lt;A href="https://localhost:8089/services/search/jobs/1599554403.2242/events" target="_blank" rel="noopener"&gt;https://localhost:8089/services/search/jobs/1599554403.2242/events&lt;/A&gt; --get -d output_mode="json"&lt;/P&gt;&lt;P&gt;output:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; "preview":false,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; "init_offset":0,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; "messages":[&amp;nbsp;],&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2020 09:31:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-event-is-not-providing-output-for-fields/m-p/518395#M145779</guid>
      <dc:creator>pallavi_prabhu_</dc:creator>
      <dc:date>2020-09-08T09:31:43Z</dc:date>
    </item>
    <item>
      <title>Re: Search event is not providing output for fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-event-is-not-providing-output-for-fields/m-p/518413#M145783</link>
      <description>&lt;OL&gt;&lt;LI&gt;&amp;nbsp;you are trying to filter events with&amp;nbsp;&lt;SPAN&gt;Urgency = High and you are getting 0 results, that's because fields are not extracted from the event. if the field is extracted from the event you could see same from fields window left side.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;A href="https://www.youtube.com/watch?v=A_dDxJww9b0&amp;amp;t=668s" target="_self"&gt;Splunk fields&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;also same reason your search is matched with 0 results, you should also specify timerange.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN&gt;-------------------------------&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Give a thumps if it solves your problem.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2020 10:57:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-event-is-not-providing-output-for-fields/m-p/518413#M145783</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-09-08T10:57:24Z</dc:date>
    </item>
    <item>
      <title>Re: Search event is not providing output for fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-event-is-not-providing-output-for-fields/m-p/518424#M145786</link>
      <description>&lt;P&gt;Adding screenshots for events created and search result. Fields are extracted but result is not listed.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="event_collector data.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10712iDC3F370EBA489510/image-size/large?v=v2&amp;amp;px=999" role="button" title="event_collector data.PNG" alt="event_collector data.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="extracted_fields Urgency.PNG" style="width: 918px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10710i08EE3FFA72575B07/image-size/large?v=v2&amp;amp;px=999" role="button" title="extracted_fields Urgency.PNG" alt="extracted_fields Urgency.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Search_using Urgency.PNG" style="width: 875px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10711i1F56F99046473188/image-size/large?v=v2&amp;amp;px=999" role="button" title="Search_using Urgency.PNG" alt="Search_using Urgency.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2020 11:26:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-event-is-not-providing-output-for-fields/m-p/518424#M145786</guid>
      <dc:creator>pallavi_prabhu_</dc:creator>
      <dc:date>2020-09-08T11:26:51Z</dc:date>
    </item>
    <item>
      <title>Re: Search event is not providing output for fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-event-is-not-providing-output-for-fields/m-p/518428#M145788</link>
      <description>&lt;P&gt;How did you add urgency=High to your search? Typing it in or selecting it from the list of values and adding it to the search?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2020 12:02:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-event-is-not-providing-output-for-fields/m-p/518428#M145788</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-09-08T12:02:09Z</dc:date>
    </item>
    <item>
      <title>Re: Search event is not providing output for fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-event-is-not-providing-output-for-fields/m-p/518432#M145789</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/129407"&gt;@thambisetty&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp; We tried both ways. In case of selecting search criteria from suggested drop down list also we are getting 0 results. Is there any search specific for HTTP event collector where event is created with json body provided as :&lt;/P&gt;&lt;DIV&gt;{&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"sourcetype":"trial",&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"event":"ITSM2",&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"fields":&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;{&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; "discription":"ITSM2 inserting data",&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"urgency":"Low"&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;}}&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Because we tried modifing above payload as :&lt;/DIV&gt;&lt;DIV&gt;{&amp;nbsp; &amp;nbsp; "sourcetype":"trial",&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; "event":&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;{&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; "discription":"ITSM2 inserting data",&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"urgency":"Low"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; }}&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;In this case search works for urgency. So Do we need to handle search criteria differently if "fields" are used while creating events?&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 08 Sep 2020 12:20:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-event-is-not-providing-output-for-fields/m-p/518432#M145789</guid>
      <dc:creator>pallavi_prabhu_</dc:creator>
      <dc:date>2020-09-08T12:20:23Z</dc:date>
    </item>
    <item>
      <title>Re: Search event is not providing output for fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-event-is-not-providing-output-for-fields/m-p/518433#M145790</link>
      <description>&lt;P&gt;yes,&amp;nbsp; you need handle search criteria differently based on how you would like to project your results in reports or dashboards.&lt;/P&gt;&lt;P&gt;and also, I think you are adding sourcetype also inside the event attribute while constructing data for HTTP event collector. if you use sourcetype field separately as event then you don't see it in events but you see new field sourcetype because this is meta field.&lt;/P&gt;&lt;PRE&gt;curl -k -H "Authorization: Splunk 12345678-1234-1234-1234-1234567890AB" https://mysplunkserver.example.com:8088/services/collector/event -d '{"sourcetype": "my_sample_data", "event": "http auth ftw!"}'&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2020 12:34:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-event-is-not-providing-output-for-fields/m-p/518433#M145790</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-09-08T12:34:08Z</dc:date>
    </item>
  </channel>
</rss>

