<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: _meta fields: why am I unable to search for all of the events? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/meta-fields-why-am-I-unable-to-search-for-all-of-the-events/m-p/446587#M167614</link>
    <description>&lt;P&gt;You are using indexed time extration. You have to supply required fileds props and transforms to the search peers. If you are using heavy forwarder confs should  to be in hf.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.4/Data/Configureindex-timefieldextraction"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.4/Data/Configureindex-timefieldextraction&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 16 Feb 2019 05:08:34 GMT</pubDate>
    <dc:creator>vasanthmss</dc:creator>
    <dc:date>2019-02-16T05:08:34Z</dc:date>
    <item>
      <title>_meta fields: why am I unable to search for all of the events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/meta-fields-why-am-I-unable-to-search-for-all-of-the-events/m-p/446584#M167611</link>
      <description>&lt;P&gt;I am not able to search for all of the events from the fields. When i try field::value , I can see all of the events. But with field=value , only some of the events are searchable.&lt;BR /&gt;
updated my fields.conf with [field] INDEXED = true , but do i also need to update my inputs.conf with the fields and its values? There are going to be more values for the fields, and it can be hard to update all of them? &lt;/P&gt;</description>
      <pubDate>Fri, 07 Sep 2018 18:45:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/meta-fields-why-am-I-unable-to-search-for-all-of-the-events/m-p/446584#M167611</guid>
      <dc:creator>godman</dc:creator>
      <dc:date>2018-09-07T18:45:18Z</dc:date>
    </item>
    <item>
      <title>Re: _meta fields: why am I unable to search for all of the events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/meta-fields-why-am-I-unable-to-search-for-all-of-the-events/m-p/446585#M167612</link>
      <description>&lt;P&gt;Hi @godman,&lt;/P&gt;

&lt;P&gt;Not sure if this helps, but I stumbled upon this answers post that seems similar to yours. Thought I'd pass it along just in case. &lt;A href="https://answers.splunk.com/answers/389567/why-is-a-search-for-fields-added-with-meta-in-inpu.html"&gt;https://answers.splunk.com/answers/389567/why-is-a-search-for-fields-added-with-meta-in-inpu.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Sep 2018 19:11:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/meta-fields-why-am-I-unable-to-search-for-all-of-the-events/m-p/446585#M167612</guid>
      <dc:creator>mstjohn_splunk</dc:creator>
      <dc:date>2018-09-07T19:11:35Z</dc:date>
    </item>
    <item>
      <title>Re: _meta fields: why am I unable to search for all of the events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/meta-fields-why-am-I-unable-to-search-for-all-of-the-events/m-p/446586#M167613</link>
      <description>&lt;P&gt;In this example they only have one value for the field and in my case i have many values for each field and i am not able to add all of them to the inputs.conf .&lt;/P&gt;</description>
      <pubDate>Fri, 07 Sep 2018 20:32:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/meta-fields-why-am-I-unable-to-search-for-all-of-the-events/m-p/446586#M167613</guid>
      <dc:creator>godman</dc:creator>
      <dc:date>2018-09-07T20:32:21Z</dc:date>
    </item>
    <item>
      <title>Re: _meta fields: why am I unable to search for all of the events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/meta-fields-why-am-I-unable-to-search-for-all-of-the-events/m-p/446587#M167614</link>
      <description>&lt;P&gt;You are using indexed time extration. You have to supply required fileds props and transforms to the search peers. If you are using heavy forwarder confs should  to be in hf.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.4/Data/Configureindex-timefieldextraction"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.4/Data/Configureindex-timefieldextraction&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Feb 2019 05:08:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/meta-fields-why-am-I-unable-to-search-for-all-of-the-events/m-p/446587#M167614</guid>
      <dc:creator>vasanthmss</dc:creator>
      <dc:date>2019-02-16T05:08:34Z</dc:date>
    </item>
  </channel>
</rss>

