<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Interesting fields generated from the AWS Add-On not showing up in Search&amp;amp;Reporting App in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Interesting-fields-generated-from-the-AWS-Add-On-not-showing-up/m-p/629573#M218708</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Were you able to figure out what was causing this issue? I am experiencing the same problem within my environment.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 03 Feb 2023 21:14:19 GMT</pubDate>
    <dc:creator>dannyrm</dc:creator>
    <dc:date>2023-02-03T21:14:19Z</dc:date>
    <item>
      <title>Interesting fields generated from the AWS Add-On not showing up in Search&amp;Reporting App?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Interesting-fields-generated-from-the-AWS-Add-On-not-showing-up/m-p/535525#M151353</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;I have a CloudTrail data source feeding into the AWS Add-On app on a single-instance Splunk deployment.&lt;BR /&gt;&lt;BR /&gt;If I go to the AWS app and do a search from within that app, Splunk is able to extract all the interesting fields and populate them into key-vaule pairs just fine.&lt;BR /&gt;&lt;BR /&gt;However, I've built a dashboard using that data source and interesting fields in the S&amp;amp;R app and Splunk does not populate those same key-vaule pairs as it would in the AWS app.&lt;BR /&gt;&lt;BR /&gt;The only way to extract those key-vaule pairs from within the S&amp;amp;R app is to do a 'spath' search which is not the best way to build the searches in the dashboard.&lt;BR /&gt;&lt;BR /&gt;I've already checked the fields settings and it's showing all the AWS fields enabled globally in the permissions section.&lt;BR /&gt;&lt;BR /&gt;Has anybody experienced this issue before, or have any ideas where to poke at to get the fields to be extracted globally?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2023 22:16:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Interesting-fields-generated-from-the-AWS-Add-On-not-showing-up/m-p/535525#M151353</guid>
      <dc:creator>mcirrici</dc:creator>
      <dc:date>2023-02-03T22:16:06Z</dc:date>
    </item>
    <item>
      <title>Re: Interesting fields generated from the AWS Add-On not showing up in Search&amp;Reporting App</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Interesting-fields-generated-from-the-AWS-Add-On-not-showing-up/m-p/629573#M218708</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Were you able to figure out what was causing this issue? I am experiencing the same problem within my environment.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2023 21:14:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Interesting-fields-generated-from-the-AWS-Add-On-not-showing-up/m-p/629573#M218708</guid>
      <dc:creator>dannyrm</dc:creator>
      <dc:date>2023-02-03T21:14:19Z</dc:date>
    </item>
  </channel>
</rss>

