<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Fields are not showing in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Fields-are-not-showing/m-p/539472#M152566</link>
    <description>&lt;P&gt;yes searching in verbose mode&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 11 Feb 2021 13:57:32 GMT</pubDate>
    <dc:creator>sasankganta</dc:creator>
    <dc:date>2021-02-11T13:57:32Z</dc:date>
    <item>
      <title>Fields are not showing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Fields-are-not-showing/m-p/539458#M152563</link>
      <description>&lt;P&gt;I have raw event like : time action severity host , etc.,&amp;nbsp;&lt;/P&gt;&lt;P&gt;But when I checked interesting filed action filed is not showing. All the logs are related to&amp;nbsp; mcafee getting from tcp:9997&lt;/P&gt;&lt;P&gt;Can some one please let me know what can be the issue and what actions can I take to correct this ?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 13:30:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Fields-are-not-showing/m-p/539458#M152563</guid>
      <dc:creator>sasankganta</dc:creator>
      <dc:date>2021-02-11T13:30:03Z</dc:date>
    </item>
    <item>
      <title>Re: Fields are not showing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Fields-are-not-showing/m-p/539464#M152565</link>
      <description>&lt;P&gt;Are you searching in Verbose Mode?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 13:47:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Fields-are-not-showing/m-p/539464#M152565</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-02-11T13:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: Fields are not showing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Fields-are-not-showing/m-p/539472#M152566</link>
      <description>&lt;P&gt;yes searching in verbose mode&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 13:57:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Fields-are-not-showing/m-p/539472#M152566</guid>
      <dc:creator>sasankganta</dc:creator>
      <dc:date>2021-02-11T13:57:32Z</dc:date>
    </item>
    <item>
      <title>Re: Fields are not showing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Fields-are-not-showing/m-p/539473#M152567</link>
      <description>&lt;P&gt;Tried in all search modes still the same issue, raw event is showing "action"&amp;nbsp; , but interesting filed it's not showing action field&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 13:59:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Fields-are-not-showing/m-p/539473#M152567</guid>
      <dc:creator>sasankganta</dc:creator>
      <dc:date>2021-02-11T13:59:39Z</dc:date>
    </item>
    <item>
      <title>Re: Fields are not showing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Fields-are-not-showing/m-p/539476#M152568</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230155"&gt;@sasankganta&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Splunk automatically recognizes fields when they are in the format "field_name=field_value".&lt;/P&gt;&lt;P&gt;Otherwise you have to extract them and you have two choices:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;use an Add-on that already contains all the field extractions (e.g. Splunk_TA_Windows);&lt;/LI&gt;&lt;LI&gt;manually extract all the fields you need.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;there's a third choice if you have a csv or a json file, but it isn't your case.&lt;/P&gt;&lt;P&gt;Anyway,&amp;nbsp;are you using an Add-on containing the field extractions?&lt;/P&gt;&lt;P&gt;if not, you have to create the fields extractions.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 14:02:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Fields-are-not-showing/m-p/539476#M152568</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-02-11T14:02:44Z</dc:date>
    </item>
    <item>
      <title>Re: Fields are not showing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Fields-are-not-showing/m-p/539486#M152572</link>
      <description>&lt;P&gt;I don't think here i can extract fields , because it's a Intrusion detection system data model and we directly get mcafee logs from tcp:9997&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 14:29:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Fields-are-not-showing/m-p/539486#M152572</guid>
      <dc:creator>sasankganta</dc:creator>
      <dc:date>2021-02-11T14:29:05Z</dc:date>
    </item>
    <item>
      <title>Re: Fields are not showing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Fields-are-not-showing/m-p/539501#M152574</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230155"&gt;@sasankganta&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;yes, you're receiving McAfee logs from tcp:9997 but after logs&amp;nbsp; are indexed, you have to parse your logs to extract fields before archiving in Data Model.&lt;/P&gt;&lt;P&gt;Is there an app for McAfee in your Search Head?&lt;/P&gt;&lt;P&gt;If yes, try again your search inside this app.&lt;/P&gt;&lt;P&gt;Otherwise, you have to parse your logs.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 15:16:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Fields-are-not-showing/m-p/539501#M152574</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-02-11T15:16:39Z</dc:date>
    </item>
    <item>
      <title>Re: Fields are not showing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Fields-are-not-showing/m-p/539531#M152582</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230155"&gt;@sasankganta&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Did you ingest McAfee logs using correct sourcetype that mentioned in the related app?&amp;nbsp;&lt;/P&gt;&lt;P&gt;If these logs are from "McAfee ePO Syslog" your sourcetype should be "mcafee:epo:syslog". If you are ingesting using something other than this sourcetype, none of the extractions will work.&lt;/P&gt;&lt;P&gt;Can you please post a screenshot that shows your search, results and interesting fields?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 17:07:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Fields-are-not-showing/m-p/539531#M152582</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-02-11T17:07:29Z</dc:date>
    </item>
    <item>
      <title>Re: Fields are not showing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Fields-are-not-showing/m-p/540252#M152823</link>
      <description>&lt;P&gt;Hi &lt;SPAN class=""&gt;&lt;SPAN&gt;scelikok&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;These are mcafee nsm logs not&amp;nbsp;&lt;SPAN&gt;McAfee ePO Syslog&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 14:10:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Fields-are-not-showing/m-p/540252#M152823</guid>
      <dc:creator>sasankganta</dc:creator>
      <dc:date>2021-02-17T14:10:32Z</dc:date>
    </item>
    <item>
      <title>Re: Fields are not showing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Fields-are-not-showing/m-p/540255#M152824</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230155"&gt;@sasankganta&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;What are you using as a sourcetype on data input? Can you please post a sample log ?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 14:36:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Fields-are-not-showing/m-p/540255#M152824</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-02-17T14:36:42Z</dc:date>
    </item>
    <item>
      <title>Re: Fields are not showing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Fields-are-not-showing/m-p/540273#M152833</link>
      <description>&lt;P&gt;Please find the sample log :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Feb 17 00:12:22 SyslogAuditLogForwarder: time="2021-02-17 00:12:22 BRT" domain="Serasa" category="Sensor" signature="Deploying updates to "spobripsgw02"." action="Set Deployment" result="succeeded" user="Administrator" comment="N/A" delta="N/A"&lt;BR /&gt;category = Sensorcribl_pipe = br_mnshost = 10.52.225.200ids_type = networkindex = eits_ips_prod_ussignature = Deploying updates tosource = tcp:9997sourcetype = mcafee:nsm&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 16:11:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Fields-are-not-showing/m-p/540273#M152833</guid>
      <dc:creator>sasankganta</dc:creator>
      <dc:date>2021-02-17T16:11:54Z</dc:date>
    </item>
    <item>
      <title>Re: Fields are not showing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Fields-are-not-showing/m-p/540274#M152834</link>
      <description>&lt;P&gt;Also , it would be a great help if you can suggest about undefined logs and what kind these are :&amp;nbsp;&lt;/P&gt;&lt;P&gt;Feb 17 15:41:44 SyslogAlertForwarder: ....0;;; HTTP Host == 10.10.198.187:8080;;; HTTP Response Content Type == application/javascript Last-Modified: Tue, 26 Feb 2019 16:11:46 GMT;;; "&lt;BR /&gt;cribl_pipe = uk_mnshost = undefinedids_type = networkindex = eits_ips_prod_ussource = tcp:9997sourcetype = mcafee:nsm&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Feb 17 15:41:07 SyslogAlertForwarder: ...P Response Content Type == application/octet-stream;;; "&lt;BR /&gt;cribl_pipe = uk_mnshost = undefinedids_type = networkindex = eits_ips_prod_ussource = tcp:9997sourcetype = mcafee:nsm&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 16:15:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Fields-are-not-showing/m-p/540274#M152834</guid>
      <dc:creator>sasankganta</dc:creator>
      <dc:date>2021-02-17T16:15:51Z</dc:date>
    </item>
  </channel>
</rss>

