<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Fields are missing in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Fields-are-missing/m-p/683873#M233482</link>
    <description>&lt;P&gt;Here is the sample log:&lt;/P&gt;&lt;PRE&gt;{"date": "1/2/2022 00:12:22,124",  "DATA": "[http:nio-12567-exec-44] DIP: [675478-7655a-56778d-655de45565] Data: [7665-56767ed-5454656] MIM: [483748348-632637f-38648266257d] FLOW: [NEW] { SERVICE: AAP | Applicationid: iis-675456 | ACTION: START | REQ: GET data published/data/ui } DADTA -:TIME:&amp;lt;TIMESTAMP&amp;gt; (0) 1712721546785 to 1712721546885 ms GET /v8/wi/data/*, GET data/ui/wi/load/success", "tags": {"host": "GTU5656", "insuranceid": "8786578896667", "lib": "app"}}&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have around 10 services, by using below query i am getting 8 services and other 2 are not getting displayed in the table. But we can view them in events. Filed extraction is working correctly.&lt;BR /&gt;not sure why other 2 services are not showing up in the table.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;PRE&gt;index=test-index (data loaded) OR ("GET data published/data/ui" OR "GET /v8/wi/data/*" OR "GET data/ui/wi/load/success")
|rex field=_raw "DIP:\s+\[(?&amp;lt;dip&amp;gt;[^\]]+)."
|rex field=_raw "ACTION:\s+(?&amp;lt;actions&amp;gt;\w+)"
|rex dield=_raw "SERVICE:\s+(?&amp;lt;services&amp;gt;\S+)"
|search actions= start OR actions=done NOT service="null"
|eval split=services.":".actions
|timechart span=1d count by split
|eval _time=strftime(_time, "%d/%m/%Y")
|table _time *start *done&lt;/PRE&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;Current output: (DCC:DONE &amp;amp;PIP:DONE&amp;nbsp; fields are missing)&lt;/P&gt;&lt;TABLE border="1" width="800px"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="83.3125px" height="30px"&gt;_time&lt;/TD&gt;&lt;TD width="92.1771px" height="30px"&gt;AAP:START&lt;/TD&gt;&lt;TD width="93.3229px" height="30px"&gt;ACC:START&lt;/TD&gt;&lt;TD width="91.8125px" height="30px"&gt;ABB:START&lt;/TD&gt;&lt;TD width="94.4479px" height="30px"&gt;DCC:START&lt;/TD&gt;&lt;TD width="85.2188px" height="30px"&gt;PIP:START&lt;/TD&gt;&lt;TD width="87.6042px" height="30px"&gt;AAP:DONE&lt;/TD&gt;&lt;TD width="88.75px" height="30px"&gt;ACC:DONE&lt;/TD&gt;&lt;TD width="87.2292px" height="30px"&gt;ABB:DONE&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="83.3125px" height="24px"&gt;1/2/2022&lt;/TD&gt;&lt;TD width="92.1771px" height="24px"&gt;1&lt;/TD&gt;&lt;TD width="93.3229px" height="24px"&gt;100&lt;/TD&gt;&lt;TD width="91.8125px" height="24px"&gt;1&lt;/TD&gt;&lt;TD width="94.4479px" height="24px"&gt;100&lt;/TD&gt;&lt;TD width="85.2188px" height="24px"&gt;1&lt;/TD&gt;&lt;TD width="87.6042px" height="24px"&gt;1&lt;/TD&gt;&lt;TD width="88.75px" height="24px"&gt;66&lt;/TD&gt;&lt;TD width="87.2292px" height="24px"&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="83.3125px" height="24px"&gt;2/2/2022&lt;/TD&gt;&lt;TD width="92.1771px" height="24px"&gt;5&lt;/TD&gt;&lt;TD width="93.3229px" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="91.8125px" height="24px"&gt;5&lt;/TD&gt;&lt;TD width="94.4479px" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="85.2188px" height="24px"&gt;3&lt;/TD&gt;&lt;TD width="87.6042px" height="24px"&gt;3&lt;/TD&gt;&lt;TD width="88.75px" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="87.2292px" height="24px"&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="83.3125px" height="24px"&gt;3/2/2022&lt;/TD&gt;&lt;TD width="92.1771px" height="24px"&gt;10&lt;/TD&gt;&lt;TD width="93.3229px" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="91.8125px" height="24px"&gt;10&lt;/TD&gt;&lt;TD width="94.4479px" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="85.2188px" height="24px"&gt;8&lt;/TD&gt;&lt;TD width="87.6042px" height="24px"&gt;7&lt;/TD&gt;&lt;TD width="88.75px" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="87.2292px" height="24px"&gt;8&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="83.3125px" height="24px"&gt;4/2/2022&lt;/TD&gt;&lt;TD width="92.1771px" height="24px"&gt;100&lt;/TD&gt;&lt;TD width="93.3229px" height="24px"&gt;1&lt;/TD&gt;&lt;TD width="91.8125px" height="24px"&gt;100&lt;/TD&gt;&lt;TD width="94.4479px" height="24px"&gt;1&lt;/TD&gt;&lt;TD width="85.2188px" height="24px"&gt;97&lt;/TD&gt;&lt;TD width="87.6042px" height="24px"&gt;80&lt;/TD&gt;&lt;TD width="88.75px" height="24px"&gt;1&lt;/TD&gt;&lt;TD width="87.2292px" height="24px"&gt;80&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="83.3125px" height="24px"&gt;5/2/2022&lt;/TD&gt;&lt;TD width="92.1771px" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="93.3229px" height="24px"&gt;5&lt;/TD&gt;&lt;TD width="91.8125px" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="94.4479px" height="24px"&gt;5&lt;/TD&gt;&lt;TD width="85.2188px" height="24px"&gt;350&lt;/TD&gt;&lt;TD width="87.6042px" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="88.75px" height="24px"&gt;4&lt;/TD&gt;&lt;TD width="87.2292px" height="24px"&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Expected output:&lt;/P&gt;&lt;TABLE border="1" width="110%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="10%" height="30px"&gt;_time&lt;/TD&gt;&lt;TD width="10%" height="30px"&gt;AAP:START&lt;/TD&gt;&lt;TD width="10%" height="30px"&gt;ACC:START&lt;/TD&gt;&lt;TD width="10%" height="30px"&gt;ABB:START&lt;/TD&gt;&lt;TD width="10%" height="30px"&gt;DCC:START&lt;/TD&gt;&lt;TD width="10%" height="30px"&gt;PIP:START&lt;/TD&gt;&lt;TD width="10%" height="30px"&gt;AAP:DONE&lt;/TD&gt;&lt;TD width="10%" height="30px"&gt;ACC:DONE&lt;/TD&gt;&lt;TD width="10%" height="30px"&gt;ABB:DONE&lt;/TD&gt;&lt;TD width="10%" height="30px"&gt;DCC:DONE&lt;/TD&gt;&lt;TD width="10%" height="30px"&gt;PIP:DONE&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="10%" height="24px"&gt;1/2/2022&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;1&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;100&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;1&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;100&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;1&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;1&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;66&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;1&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;99&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="10%" height="24px"&gt;2/2/2022&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;5&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;5&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;3&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;3&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;3&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="10%" height="24px"&gt;3/2/2022&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;10&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;10&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;8&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;7&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;8&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="10%" height="24px"&gt;4/2/2022&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;100&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;1&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;100&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;1&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;97&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;80&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;1&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;80&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;1&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;90&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="10%" height="24px"&gt;5/2/2022&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;5&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;5&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;350&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;4&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;5&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;200&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 11 Apr 2024 01:37:00 GMT</pubDate>
    <dc:creator>mahesh27</dc:creator>
    <dc:date>2024-04-11T01:37:00Z</dc:date>
    <item>
      <title>Fields are missing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Fields-are-missing/m-p/683873#M233482</link>
      <description>&lt;P&gt;Here is the sample log:&lt;/P&gt;&lt;PRE&gt;{"date": "1/2/2022 00:12:22,124",  "DATA": "[http:nio-12567-exec-44] DIP: [675478-7655a-56778d-655de45565] Data: [7665-56767ed-5454656] MIM: [483748348-632637f-38648266257d] FLOW: [NEW] { SERVICE: AAP | Applicationid: iis-675456 | ACTION: START | REQ: GET data published/data/ui } DADTA -:TIME:&amp;lt;TIMESTAMP&amp;gt; (0) 1712721546785 to 1712721546885 ms GET /v8/wi/data/*, GET data/ui/wi/load/success", "tags": {"host": "GTU5656", "insuranceid": "8786578896667", "lib": "app"}}&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have around 10 services, by using below query i am getting 8 services and other 2 are not getting displayed in the table. But we can view them in events. Filed extraction is working correctly.&lt;BR /&gt;not sure why other 2 services are not showing up in the table.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;PRE&gt;index=test-index (data loaded) OR ("GET data published/data/ui" OR "GET /v8/wi/data/*" OR "GET data/ui/wi/load/success")
|rex field=_raw "DIP:\s+\[(?&amp;lt;dip&amp;gt;[^\]]+)."
|rex field=_raw "ACTION:\s+(?&amp;lt;actions&amp;gt;\w+)"
|rex dield=_raw "SERVICE:\s+(?&amp;lt;services&amp;gt;\S+)"
|search actions= start OR actions=done NOT service="null"
|eval split=services.":".actions
|timechart span=1d count by split
|eval _time=strftime(_time, "%d/%m/%Y")
|table _time *start *done&lt;/PRE&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;Current output: (DCC:DONE &amp;amp;PIP:DONE&amp;nbsp; fields are missing)&lt;/P&gt;&lt;TABLE border="1" width="800px"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="83.3125px" height="30px"&gt;_time&lt;/TD&gt;&lt;TD width="92.1771px" height="30px"&gt;AAP:START&lt;/TD&gt;&lt;TD width="93.3229px" height="30px"&gt;ACC:START&lt;/TD&gt;&lt;TD width="91.8125px" height="30px"&gt;ABB:START&lt;/TD&gt;&lt;TD width="94.4479px" height="30px"&gt;DCC:START&lt;/TD&gt;&lt;TD width="85.2188px" height="30px"&gt;PIP:START&lt;/TD&gt;&lt;TD width="87.6042px" height="30px"&gt;AAP:DONE&lt;/TD&gt;&lt;TD width="88.75px" height="30px"&gt;ACC:DONE&lt;/TD&gt;&lt;TD width="87.2292px" height="30px"&gt;ABB:DONE&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="83.3125px" height="24px"&gt;1/2/2022&lt;/TD&gt;&lt;TD width="92.1771px" height="24px"&gt;1&lt;/TD&gt;&lt;TD width="93.3229px" height="24px"&gt;100&lt;/TD&gt;&lt;TD width="91.8125px" height="24px"&gt;1&lt;/TD&gt;&lt;TD width="94.4479px" height="24px"&gt;100&lt;/TD&gt;&lt;TD width="85.2188px" height="24px"&gt;1&lt;/TD&gt;&lt;TD width="87.6042px" height="24px"&gt;1&lt;/TD&gt;&lt;TD width="88.75px" height="24px"&gt;66&lt;/TD&gt;&lt;TD width="87.2292px" height="24px"&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="83.3125px" height="24px"&gt;2/2/2022&lt;/TD&gt;&lt;TD width="92.1771px" height="24px"&gt;5&lt;/TD&gt;&lt;TD width="93.3229px" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="91.8125px" height="24px"&gt;5&lt;/TD&gt;&lt;TD width="94.4479px" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="85.2188px" height="24px"&gt;3&lt;/TD&gt;&lt;TD width="87.6042px" height="24px"&gt;3&lt;/TD&gt;&lt;TD width="88.75px" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="87.2292px" height="24px"&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="83.3125px" height="24px"&gt;3/2/2022&lt;/TD&gt;&lt;TD width="92.1771px" height="24px"&gt;10&lt;/TD&gt;&lt;TD width="93.3229px" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="91.8125px" height="24px"&gt;10&lt;/TD&gt;&lt;TD width="94.4479px" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="85.2188px" height="24px"&gt;8&lt;/TD&gt;&lt;TD width="87.6042px" height="24px"&gt;7&lt;/TD&gt;&lt;TD width="88.75px" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="87.2292px" height="24px"&gt;8&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="83.3125px" height="24px"&gt;4/2/2022&lt;/TD&gt;&lt;TD width="92.1771px" height="24px"&gt;100&lt;/TD&gt;&lt;TD width="93.3229px" height="24px"&gt;1&lt;/TD&gt;&lt;TD width="91.8125px" height="24px"&gt;100&lt;/TD&gt;&lt;TD width="94.4479px" height="24px"&gt;1&lt;/TD&gt;&lt;TD width="85.2188px" height="24px"&gt;97&lt;/TD&gt;&lt;TD width="87.6042px" height="24px"&gt;80&lt;/TD&gt;&lt;TD width="88.75px" height="24px"&gt;1&lt;/TD&gt;&lt;TD width="87.2292px" height="24px"&gt;80&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="83.3125px" height="24px"&gt;5/2/2022&lt;/TD&gt;&lt;TD width="92.1771px" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="93.3229px" height="24px"&gt;5&lt;/TD&gt;&lt;TD width="91.8125px" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="94.4479px" height="24px"&gt;5&lt;/TD&gt;&lt;TD width="85.2188px" height="24px"&gt;350&lt;/TD&gt;&lt;TD width="87.6042px" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="88.75px" height="24px"&gt;4&lt;/TD&gt;&lt;TD width="87.2292px" height="24px"&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Expected output:&lt;/P&gt;&lt;TABLE border="1" width="110%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="10%" height="30px"&gt;_time&lt;/TD&gt;&lt;TD width="10%" height="30px"&gt;AAP:START&lt;/TD&gt;&lt;TD width="10%" height="30px"&gt;ACC:START&lt;/TD&gt;&lt;TD width="10%" height="30px"&gt;ABB:START&lt;/TD&gt;&lt;TD width="10%" height="30px"&gt;DCC:START&lt;/TD&gt;&lt;TD width="10%" height="30px"&gt;PIP:START&lt;/TD&gt;&lt;TD width="10%" height="30px"&gt;AAP:DONE&lt;/TD&gt;&lt;TD width="10%" height="30px"&gt;ACC:DONE&lt;/TD&gt;&lt;TD width="10%" height="30px"&gt;ABB:DONE&lt;/TD&gt;&lt;TD width="10%" height="30px"&gt;DCC:DONE&lt;/TD&gt;&lt;TD width="10%" height="30px"&gt;PIP:DONE&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="10%" height="24px"&gt;1/2/2022&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;1&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;100&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;1&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;100&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;1&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;1&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;66&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;1&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;99&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="10%" height="24px"&gt;2/2/2022&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;5&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;5&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;3&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;3&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;3&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="10%" height="24px"&gt;3/2/2022&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;10&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;10&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;8&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;7&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;8&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="10%" height="24px"&gt;4/2/2022&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;100&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;1&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;100&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;1&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;97&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;80&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;1&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;80&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;1&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;90&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="10%" height="24px"&gt;5/2/2022&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;5&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;5&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;350&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;4&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;0&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;5&lt;/TD&gt;&lt;TD width="10%" height="24px"&gt;200&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2024 01:37:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Fields-are-missing/m-p/683873#M233482</guid>
      <dc:creator>mahesh27</dc:creator>
      <dc:date>2024-04-11T01:37:00Z</dc:date>
    </item>
    <item>
      <title>Re: Fields are missing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Fields-are-missing/m-p/683903#M233497</link>
      <description>&lt;P&gt;This is exactly what I speculated in&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Splunk-Search/Not-all-fields-showing-up/m-p/683855/highlight/true#M233471" target="_self"&gt;your previous question&lt;/A&gt;: that your developers have left a compliant JSON, while having some structure within DATA field. &amp;nbsp;Instead of rex individual elements as if DATA is made of random text, you should utilize the structure your developers intended. &amp;nbsp;Have you tried my suggestion yesterday?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=test-index (data loaded) OR ("GET data published/data/ui" OR "GET /v8/wi/data/*" OR "GET data/ui/wi/load/success")
| rex field=DATA mode=sed "s/ *[\|}\]]/\"/g s/: *\[*/=\"/g"
| rename DATA AS _raw
| kv
|search ACTION= start OR ACTION=done NOT SERVICE="null"
|eval split=SERVICE.":".ACTION
|timechart span=1d count by split
|eval _time=strftime(_time, "%d/%m/%Y")
| table _time *START *DONE&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(Since you are running timechart, there is no need to preserver _raw, so I omitted that. &amp;nbsp;I also don't see how your last table command could give you the result you illustrated because START and DONE are capitalized.) Your sample data (only one event) gives&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;_time&lt;/TD&gt;&lt;TD&gt;AAP:START&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;01/02/2022&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;11/04/2024&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;This is the data emulation including _time conversion&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| eval _raw = "{\"date\": \"1/2/2022 00:12:22,124\",  \"DATA\": \"[http:nio-12567-exec-44] DIP: [675478-7655a-56778d-655de45565] Data: [7665-56767ed-5454656] MIM: [483748348-632637f-38648266257d] FLOW: [NEW] { SERVICE: AAP | Applicationid: iis-675456 | ACTION: START | REQ: GET data published/data/ui } DADTA -:TIME:&amp;lt;TIMESTAMP&amp;gt; (0) 1712721546785 to 1712721546885 ms GET /v8/wi/data/*, GET data/ui/wi/load/success\", \"tags\": {\"host\": \"GTU5656\", \"insuranceid\": \"8786578896667\", \"lib\": \"app\"}}"
| spath
| eval _time = strptime(date, "%d/%m/%Y %H:%M:%S,%f")
``` the above emulates
index=test-index (data loaded) OR ("GET data published/data/ui" OR "GET /v8/wi/data/*" OR "GET data/ui/wi/load/success")
```&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Play with it and compare to real data. &amp;nbsp;If this doesn't work for select events, you need to post samples of those events.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2024 13:25:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Fields-are-missing/m-p/683903#M233497</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-04-11T13:25:57Z</dc:date>
    </item>
    <item>
      <title>Re: Fields are missing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Fields-are-missing/m-p/683916#M233500</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33901"&gt;@yuanliu&lt;/a&gt;&amp;nbsp;, yes i tried the below query, but i getting 0 results&lt;/P&gt;&lt;PRE&gt;index=test-index (data loaded) OR ("GET data published/data/ui" OR "GET /v8/wi/data/*" OR "GET data/ui/wi/load/success")
| rex field=DATA mode=sed "s/ *[\|}\]]/\"/g s/: *\[*/=\"/g"
| rename DATA AS _raw
| kv
|search ACTION= start OR ACTION=done NOT SERVICE="null"
|eval split=SERVICE.":".ACTION
|timechart span=1d count by split
|eval _time=strftime(_time, "%d/%m/%Y")
| table _time *START *DONE&lt;/PRE&gt;</description>
      <pubDate>Thu, 11 Apr 2024 14:37:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Fields-are-missing/m-p/683916#M233500</guid>
      <dc:creator>mahesh27</dc:creator>
      <dc:date>2024-04-11T14:37:51Z</dc:date>
    </item>
    <item>
      <title>Re: Fields are missing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Fields-are-missing/m-p/683974#M233509</link>
      <description>&lt;P&gt;Have you compared emulation with real data? &amp;nbsp;Also, really get rid of that table command which can be in the way. (You can add some formatting after you verify that outputs are satisfactory.) &amp;nbsp;Is there some real data that you can share? (Anonymize as needed but take care to preserve precise structure.) &amp;nbsp;Using emulation, the output is not zero. &amp;nbsp;Clearly, actual data is different from what you posted above.&lt;/P&gt;&lt;P&gt;Run this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| eval _raw = "{\"date\": \"1/2/2022 00:12:22,124\",  \"DATA\": \"[http:nio-12567-exec-44] DIP: [675478-7655a-56778d-655de45565] Data: [7665-56767ed-5454656] MIM: [483748348-632637f-38648266257d] FLOW: [NEW] { SERVICE: AAP | Applicationid: iis-675456 | ACTION: START | REQ: GET data published/data/ui } DADTA -:TIME:&amp;lt;TIMESTAMP&amp;gt; (0) 1712721546785 to 1712721546885 ms GET /v8/wi/data/*, GET data/ui/wi/load/success\", \"tags\": {\"host\": \"GTU5656\", \"insuranceid\": \"8786578896667\", \"lib\": \"app\"}}"
| spath
| eval _time = strptime(date, "%d/%m/%Y %H:%M:%S,%f")
``` the above emulates
index=test-index (data loaded) OR ("GET data published/data/ui" OR "GET /v8/wi/data/*" OR "GET data/ui/wi/load/success")
```
| rex field=DATA mode=sed "s/ *[\|}\]]/\"/g s/: *\[*/=\"/g"
| rename DATA AS _raw
| kv
|search ACTION= start OR ACTION=done NOT SERVICE="null"
|eval split=SERVICE.":".ACTION
|timechart span=1d count by split
|eval _time=strftime(_time, "%d/%m/%Y")
| table _time *START *DONE&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you get the same results as I did in the previous comment? (I do not encourage use of screenshot to show search or results, but I had already shared them in text previously. So, here you go for a screenshot.)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2024-04-11 at 2.27.15 PM.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30371iC0C328802B7D90BF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2024-04-11 at 2.27.15 PM.png" alt="Screen Shot 2024-04-11 at 2.27.15 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2024 21:30:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Fields-are-missing/m-p/683974#M233509</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-04-11T21:30:40Z</dc:date>
    </item>
  </channel>
</rss>

