<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why do I no longer see certain fields being parsed in Splunk search results? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-do-I-no-longer-see-certain-fields-being-parsed-in-Splunk/m-p/210024#M61419</link>
    <description>&lt;P&gt;That was the issues -thanks!&lt;/P&gt;</description>
    <pubDate>Mon, 22 Feb 2016 14:48:43 GMT</pubDate>
    <dc:creator>NimrodSky</dc:creator>
    <dc:date>2016-02-22T14:48:43Z</dc:date>
    <item>
      <title>Why do I no longer see certain fields being parsed in Splunk search results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-I-no-longer-see-certain-fields-being-parsed-in-Splunk/m-p/210022#M61417</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;For some reason, Splunk is not parsing data anymore - whenever I load new files or forward syslog, while I see the raw event in the search, I only get some generic fields such as - sourcetype, splunk_server, index, linecount, and _time.&lt;/P&gt;

&lt;P&gt;Nothing was changed as far as I know - no new version, no changed configurations.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2016 09:09:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-I-no-longer-see-certain-fields-being-parsed-in-Splunk/m-p/210022#M61417</guid>
      <dc:creator>NimrodSky</dc:creator>
      <dc:date>2016-02-22T09:09:58Z</dc:date>
    </item>
    <item>
      <title>Re: Why do I no longer see certain fields being parsed in Splunk search results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-I-no-longer-see-certain-fields-being-parsed-in-Splunk/m-p/210023#M61418</link>
      <description>&lt;P&gt;Are you by any chance searching in Fast Mode? If so you will see no field extractions. Change back to Smart Mode. &lt;/P&gt;

&lt;P&gt;If you have the same problem then make sure your field extractions are correctly loads. Run &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;$SPLUNK_HOME/bin/splunk/cmd btool props list --debug
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This will show you all the field extractions present and which file they are loaded from.l If you don't see yours then check where your props and transforms entries are. &lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2016 14:33:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-I-no-longer-see-certain-fields-being-parsed-in-Splunk/m-p/210023#M61418</guid>
      <dc:creator>jplumsdaine22</dc:creator>
      <dc:date>2016-02-22T14:33:18Z</dc:date>
    </item>
    <item>
      <title>Re: Why do I no longer see certain fields being parsed in Splunk search results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-I-no-longer-see-certain-fields-being-parsed-in-Splunk/m-p/210024#M61419</link>
      <description>&lt;P&gt;That was the issues -thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2016 14:48:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-I-no-longer-see-certain-fields-being-parsed-in-Splunk/m-p/210024#M61419</guid>
      <dc:creator>NimrodSky</dc:creator>
      <dc:date>2016-02-22T14:48:43Z</dc:date>
    </item>
    <item>
      <title>Re: Why do I no longer see certain fields being parsed in Splunk search results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-I-no-longer-see-certain-fields-being-parsed-in-Splunk/m-p/210025#M61420</link>
      <description>&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Fast mode gets me at least once a week&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2016 16:57:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-I-no-longer-see-certain-fields-being-parsed-in-Splunk/m-p/210025#M61420</guid>
      <dc:creator>jplumsdaine22</dc:creator>
      <dc:date>2016-02-22T16:57:01Z</dc:date>
    </item>
  </channel>
</rss>

