<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Apache logs relevant field name not showing in details log in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-is-apache-logs-relevant-field-name-not-showing-in-details/m-p/588815#M205057</link>
    <description>&lt;P&gt;The issue seems to stem, at least in part, from the sourcetype "access-too_small".&amp;nbsp; It's unlikely any add-on uses that sourcetype so none will extract any fields for it.&lt;/P&gt;&lt;P&gt;The "-too_small" issue usually arises when the input does not specify a sourcetype and there's not enough data for Splunk to analyze and make a guess about the sourcetype.&amp;nbsp; Make sure the inputs.conf file with the &lt;FONT face="courier new,courier"&gt;[monitor:///var/log/apache2/access.log]&lt;/FONT&gt; stanza has a &lt;FONT face="courier new,courier"&gt;sourcetype&lt;/FONT&gt; setting,&lt;/P&gt;</description>
    <pubDate>Fri, 11 Mar 2022 20:35:32 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2022-03-11T20:35:32Z</dc:date>
    <item>
      <title>Why is apache logs relevant field name not showing in details log?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-apache-logs-relevant-field-name-not-showing-in-details/m-p/588788#M205047</link>
      <description>&lt;P&gt;Hello ,&lt;/P&gt;
&lt;P&gt;I have installed forwarder on Linux system and able to see logs in searches but the when i open a detailed log the field &amp;amp; value is missing for the relevant part of raw log.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jaycybersec_1-1647022736429.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18462iA1EDB98259E94599/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Jaycybersec_1-1647022736429.png" alt="Jaycybersec_1-1647022736429.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;All the useful details are missing in field.&lt;/P&gt;
&lt;P&gt;Ip address, status code, bytes, user agent name, method used etc.. are missing.&lt;/P&gt;
&lt;P&gt;can anyone guide here how to see those relevant things inside events.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 19:26:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-apache-logs-relevant-field-name-not-showing-in-details/m-p/588788#M205047</guid>
      <dc:creator>Jaycybersec</dc:creator>
      <dc:date>2022-03-11T19:26:20Z</dc:date>
    </item>
    <item>
      <title>Re: Apache logs relevant field name not showing in details log</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-apache-logs-relevant-field-name-not-showing-in-details/m-p/588800#M205051</link>
      <description>&lt;P&gt;Have you installed an app to process the events for you?&amp;nbsp; Splunk Add-on for Apache Web Server (&lt;A href="https://splunkbase.splunk.com/app/3186/" target="_blank"&gt;https://splunkbase.splunk.com/app/3186/&lt;/A&gt;) looks like a good candidate.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 19:23:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-apache-logs-relevant-field-name-not-showing-in-details/m-p/588800#M205051</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-03-11T19:23:03Z</dc:date>
    </item>
    <item>
      <title>Re: Apache logs relevant field name not showing in details log</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-apache-logs-relevant-field-name-not-showing-in-details/m-p/588812#M205054</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your response.&lt;/P&gt;&lt;P&gt;Have installed the app and restarted the service but still unable to see those relevant fields.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jaycybersec_0-1647029412755.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18468iF3EEAE6940458ED9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Jaycybersec_0-1647029412755.png" alt="Jaycybersec_0-1647029412755.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jaycybersec_1-1647029439147.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18469i713B0E2F43A5DA2B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Jaycybersec_1-1647029439147.png" alt="Jaycybersec_1-1647029439147.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 20:10:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-apache-logs-relevant-field-name-not-showing-in-details/m-p/588812#M205054</guid>
      <dc:creator>Jaycybersec</dc:creator>
      <dc:date>2022-03-11T20:10:46Z</dc:date>
    </item>
    <item>
      <title>Re: Apache logs relevant field name not showing in details log</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-apache-logs-relevant-field-name-not-showing-in-details/m-p/588815#M205057</link>
      <description>&lt;P&gt;The issue seems to stem, at least in part, from the sourcetype "access-too_small".&amp;nbsp; It's unlikely any add-on uses that sourcetype so none will extract any fields for it.&lt;/P&gt;&lt;P&gt;The "-too_small" issue usually arises when the input does not specify a sourcetype and there's not enough data for Splunk to analyze and make a guess about the sourcetype.&amp;nbsp; Make sure the inputs.conf file with the &lt;FONT face="courier new,courier"&gt;[monitor:///var/log/apache2/access.log]&lt;/FONT&gt; stanza has a &lt;FONT face="courier new,courier"&gt;sourcetype&lt;/FONT&gt; setting,&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 20:35:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-apache-logs-relevant-field-name-not-showing-in-details/m-p/588815#M205057</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-03-11T20:35:32Z</dc:date>
    </item>
    <item>
      <title>Re: Apache logs relevant field name not showing in details log</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-apache-logs-relevant-field-name-not-showing-in-details/m-p/588825#M205062</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;i have done the suggested steps and it's working fine and showing the relevant field.&lt;/P&gt;&lt;P&gt;Thanks .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jaycybersec_0-1647066066085.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18471iE1754C971511AA75/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Jaycybersec_0-1647066066085.png" alt="Jaycybersec_0-1647066066085.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jaycybersec_1-1647066077530.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18472iA0FAA5048B6ED3D6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Jaycybersec_1-1647066077530.png" alt="Jaycybersec_1-1647066077530.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 12 Mar 2022 06:21:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-apache-logs-relevant-field-name-not-showing-in-details/m-p/588825#M205062</guid>
      <dc:creator>Jaycybersec</dc:creator>
      <dc:date>2022-03-12T06:21:28Z</dc:date>
    </item>
    <item>
      <title>Re: Apache logs relevant field name not showing in details log</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-apache-logs-relevant-field-name-not-showing-in-details/m-p/588830#M205066</link>
      <description>&lt;P&gt;Great!&amp;nbsp;&amp;nbsp;If your problem is resolved, then please click the "Accept as Solution" button to help future readers.&lt;/P&gt;</description>
      <pubDate>Sat, 12 Mar 2022 13:23:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-apache-logs-relevant-field-name-not-showing-in-details/m-p/588830#M205066</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-03-12T13:23:05Z</dc:date>
    </item>
  </channel>
</rss>

