<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't See Newly Creating Fields in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Can-t-See-Newly-Creating-Fields/m-p/110842#M29004</link>
    <description>&lt;P&gt;Update:  I just discovered that the index associated with this search is a "summary index".  My question now is does this new information affect the process of creating fields in any way?&lt;/P&gt;</description>
    <pubDate>Fri, 17 Jan 2014 22:08:22 GMT</pubDate>
    <dc:creator>OldManEd</dc:creator>
    <dc:date>2014-01-17T22:08:22Z</dc:date>
    <item>
      <title>Can't See Newly Creating Fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-t-See-Newly-Creating-Fields/m-p/110831#M28993</link>
      <description>&lt;P&gt;I just created a new search field name going through the following process;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;1.  Run a simple search
2.  Select “Extract Fields”
3.  Edit the regex &amp;amp; run a “test” to verify that it works, save it and give it a name
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Then I review the Manager&amp;gt;Fields&amp;gt;Field extractions web page searching on “App context” = Search (search) and “Owner” = Me, and there it is.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Name                              Type     Extraction/Transform                             Owner   App      Sharing              Status    Actions
crm_cid_log : EXTRACT-CPC_ACCTNO  Inline   (?i)&amp;lt;BILLINGACCOUNTNUMBER&amp;gt;(?P&amp;lt;CPC_ACCTNO&amp;gt;[^&amp;lt;]+)  myname  search  Global | Permissions   Enabled  Move | Delete
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Under permissions I have “All apps” selected and under “Roles” I have Everyone Read &amp;amp; Write.&lt;/P&gt;

&lt;P&gt;Now, when I go back and run the same search, on the left side on the Web page I do not see the field name.  When I go into the “View all nn fields”, my new field is not there either.&lt;/P&gt;

&lt;P&gt;Can anyone give me an idea of what’s going on?&lt;/P&gt;

&lt;P&gt;~Ed&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2014 16:41:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-t-See-Newly-Creating-Fields/m-p/110831#M28993</guid>
      <dc:creator>OldManEd</dc:creator>
      <dc:date>2014-01-13T16:41:14Z</dc:date>
    </item>
    <item>
      <title>Re: Can't See Newly Creating Fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-t-See-Newly-Creating-Fields/m-p/110832#M28994</link>
      <description>&lt;P&gt;Try the following:&lt;/P&gt;

&lt;P&gt;&lt;BASE_SEARCH&gt; | extract reload=T&lt;/BASE_SEARCH&gt;&lt;/P&gt;

&lt;P&gt;This should force Splunk to reload your field definitions and run them again.&lt;/P&gt;

&lt;P&gt;I've noticed that sometimes it takes Splunk a while to recognize a new field definition.&lt;/P&gt;

&lt;P&gt;Hope this helps&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2014 18:47:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-t-See-Newly-Creating-Fields/m-p/110832#M28994</guid>
      <dc:creator>aholzer</dc:creator>
      <dc:date>2014-01-13T18:47:23Z</dc:date>
    </item>
    <item>
      <title>Re: Can't See Newly Creating Fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-t-See-Newly-Creating-Fields/m-p/110833#M28995</link>
      <description>&lt;P&gt;I tried the | extract reload=T and, unfortunately, no luck.  Thanks anyway.&lt;BR /&gt;
~Ed&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2014 18:52:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-t-See-Newly-Creating-Fields/m-p/110833#M28995</guid>
      <dc:creator>OldManEd</dc:creator>
      <dc:date>2014-01-13T18:52:34Z</dc:date>
    </item>
    <item>
      <title>Re: Can't See Newly Creating Fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-t-See-Newly-Creating-Fields/m-p/110834#M28996</link>
      <description>&lt;P&gt;This has helped me a lot of time with similar issue. Just restart your Splunk Instance and see if those fields are available. This is not a standard solution, but may work for you.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2014 19:59:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-t-See-Newly-Creating-Fields/m-p/110834#M28996</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-01-13T19:59:42Z</dc:date>
    </item>
    <item>
      <title>Re: Can't See Newly Creating Fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-t-See-Newly-Creating-Fields/m-p/110835#M28997</link>
      <description>&lt;P&gt;That was the first thing that I tried was the restart.  Unfortunately it was no help this time.&lt;BR /&gt;
~Ed&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2014 20:02:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-t-See-Newly-Creating-Fields/m-p/110835#M28997</guid>
      <dc:creator>OldManEd</dc:creator>
      <dc:date>2014-01-13T20:02:10Z</dc:date>
    </item>
    <item>
      <title>Re: Can't See Newly Creating Fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-t-See-Newly-Creating-Fields/m-p/110836#M28998</link>
      <description>&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;Did you follow these guidelines for field names? Field names should contain only letters, numbers and underscores. They must start with a letter. I know that you can use field names with spaces in them - but I have found that these guidelines work in all contexts and without quotation marks.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Do all of the events have this field? I assume that the answer to this is yes, because you ran the same simple search twice. But what happens if you search for &lt;CODE&gt;CPC_ACCTNO=*&lt;/CODE&gt;&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Remember that field names are case-sensitive&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;The fields sidebar (and even the "show all fields" popup window) have thresholds - a field must be present in a minimum % of events in order to appear in the list.&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Also, when I look at this:&lt;BR /&gt;&lt;BR /&gt;
&lt;CODE&gt;(?i)&amp;lt;BILLINGACCOUNTNUMBER&amp;gt;(?P&amp;lt;CPC_ACCTNO&amp;gt;[^&amp;lt;]+)&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;I see a possible problem with the regular expression. Edit the regular expression to match the following and it might help - if it does, there might be a bug in the field extractor:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;(?i)\&amp;lt;BILLINGACCOUNTNUMBER&amp;gt;(?P&amp;lt;CPC_ACCTNO&amp;gt;[^&amp;lt;]+)&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;(see the  backslash (\) that I put as the 5th character?)&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2014 21:36:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-t-See-Newly-Creating-Fields/m-p/110836#M28998</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2014-01-13T21:36:14Z</dc:date>
    </item>
    <item>
      <title>Re: Can't See Newly Creating Fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-t-See-Newly-Creating-Fields/m-p/110837#M28999</link>
      <description>&lt;P&gt;OK, follow-up newbie question.  I haven't seen any log files come in to the system since I created the new fields.  Do I have to wait for something new to come in or should the fields be there once I create the new fields?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2014 21:36:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-t-See-Newly-Creating-Fields/m-p/110837#M28999</guid>
      <dc:creator>OldManEd</dc:creator>
      <dc:date>2014-01-13T21:36:27Z</dc:date>
    </item>
    <item>
      <title>Re: Can't See Newly Creating Fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-t-See-Newly-Creating-Fields/m-p/110838#M29000</link>
      <description>&lt;OL&gt;
&lt;LI&gt;Yes&lt;/LI&gt;
&lt;LI&gt;Most do.&lt;/LI&gt;
&lt;LI&gt;Understood.&lt;/LI&gt;
&lt;LI&gt;Understood
() added with no change.&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Now, for my newbie question from above.  I haven't seen any events come in to the system since I created the new fields.  Do I have to wait for something new to come in or should the fields be there from the old data once I create the new fields?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2014 21:53:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-t-See-Newly-Creating-Fields/m-p/110838#M29000</guid>
      <dc:creator>OldManEd</dc:creator>
      <dc:date>2014-01-13T21:53:27Z</dc:date>
    </item>
    <item>
      <title>Re: Can't See Newly Creating Fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-t-See-Newly-Creating-Fields/m-p/110839#M29001</link>
      <description>&lt;P&gt;Number 4 should read "Understood, backslash added with no change."  Sorry.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2014 21:54:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-t-See-Newly-Creating-Fields/m-p/110839#M29001</guid>
      <dc:creator>OldManEd</dc:creator>
      <dc:date>2014-01-13T21:54:21Z</dc:date>
    </item>
    <item>
      <title>Re: Can't See Newly Creating Fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-t-See-Newly-Creating-Fields/m-p/110840#M29002</link>
      <description>&lt;P&gt;One of the wonderful things about fields is that they are extracted at search time - so they apply to all data, old and new.&lt;/P&gt;

&lt;P&gt;So yes, you should be seeing your fields.&lt;/P&gt;

&lt;P&gt;I just feel that we are overlooking something obvious here. I wonder if we are looking at the wrong things - can we see&lt;/P&gt;

&lt;P&gt;1 - a sample of the data&lt;BR /&gt;&lt;BR /&gt;
2 - the search that you ran&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2014 16:19:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-t-See-Newly-Creating-Fields/m-p/110840#M29002</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2014-01-14T16:19:10Z</dc:date>
    </item>
    <item>
      <title>Re: Can't See Newly Creating Fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-t-See-Newly-Creating-Fields/m-p/110841#M29003</link>
      <description>&lt;P&gt;OK, an update here.  I tried to run the following query;&lt;/P&gt;

&lt;P&gt;index=&lt;INDEX name=""&gt; sourcetype="&lt;SOURCE type=""&gt;" | head 10000 | rex "(?i)&lt;CLIK&gt;(?P&lt;CPC_ACCTNO&gt;[^&amp;lt;]+)" | top 50 CPC_ACCTNO&lt;/CPC_ACCTNO&gt;&lt;/CLIK&gt;&lt;/SOURCE&gt;&lt;/INDEX&gt;&lt;/P&gt;

&lt;P&gt;And it worked like a champ.&lt;/P&gt;

&lt;P&gt;I don't know what's going on here.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2014 17:04:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-t-See-Newly-Creating-Fields/m-p/110841#M29003</guid>
      <dc:creator>OldManEd</dc:creator>
      <dc:date>2014-01-14T17:04:37Z</dc:date>
    </item>
    <item>
      <title>Re: Can't See Newly Creating Fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-t-See-Newly-Creating-Fields/m-p/110842#M29004</link>
      <description>&lt;P&gt;Update:  I just discovered that the index associated with this search is a "summary index".  My question now is does this new information affect the process of creating fields in any way?&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2014 22:08:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-t-See-Newly-Creating-Fields/m-p/110842#M29004</guid>
      <dc:creator>OldManEd</dc:creator>
      <dc:date>2014-01-17T22:08:22Z</dc:date>
    </item>
  </channel>
</rss>

