<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot search customized field ... in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Cannot-search-customized-field/m-p/30706#M6247</link>
    <description>&lt;P&gt;You're not telling us how your field is extracted, but I strongly suspect that what you're see is what is described here: &lt;A href="http://blogs.splunk.com/2011/10/07/cannot-search-based-on-an-extracted-field/"&gt;http://blogs.splunk.com/2011/10/07/cannot-search-based-on-an-extracted-field/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Basically you're likely extracting a field value that isn't part of indexed data, or only part of a token in indexed data. For instance, in the first case, the field could have been extracted in something like this manner:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[myfieldextraction]
REGEX = (matchsomething)
FORMAT = myfield::someothertext
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;...so the field would have the value "someothertext" even though that value doesn't actually exist at all in the index.&lt;/P&gt;

&lt;P&gt;Or, in the second case, the extraction would look something like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[myotherfieldextraction]
REGEX = (matchjust)apartofaword
FORMAT = myotherfield::$1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If any of these apply to your extraction, you are very likely seeing the effects that the blog post I linked to talks about.&lt;/P&gt;</description>
    <pubDate>Mon, 13 May 2013 06:12:29 GMT</pubDate>
    <dc:creator>Ayn</dc:creator>
    <dc:date>2013-05-13T06:12:29Z</dc:date>
    <item>
      <title>Cannot search customized field ...</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Cannot-search-customized-field/m-p/30705#M6246</link>
      <description>&lt;P&gt;I can search by the following field key,&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;test_field=*
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;and Splunk Web displayed the lists.&lt;BR /&gt;
Then I select the "test_field=testA"(so following keywords), but displayed no lists.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;test_field=* test_field=testA
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And the following search command display no result. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;test_field=testA
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Furthermore, I add "| search" between the two kewords, then displayed properly.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;test_field=* | search test_field=testA
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Why is this happened ?&lt;BR /&gt;
Thank you for helping.&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2013 04:56:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Cannot-search-customized-field/m-p/30705#M6246</guid>
      <dc:creator>sunrise</dc:creator>
      <dc:date>2013-05-13T04:56:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot search customized field ...</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Cannot-search-customized-field/m-p/30706#M6247</link>
      <description>&lt;P&gt;You're not telling us how your field is extracted, but I strongly suspect that what you're see is what is described here: &lt;A href="http://blogs.splunk.com/2011/10/07/cannot-search-based-on-an-extracted-field/"&gt;http://blogs.splunk.com/2011/10/07/cannot-search-based-on-an-extracted-field/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Basically you're likely extracting a field value that isn't part of indexed data, or only part of a token in indexed data. For instance, in the first case, the field could have been extracted in something like this manner:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[myfieldextraction]
REGEX = (matchsomething)
FORMAT = myfield::someothertext
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;...so the field would have the value "someothertext" even though that value doesn't actually exist at all in the index.&lt;/P&gt;

&lt;P&gt;Or, in the second case, the extraction would look something like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[myotherfieldextraction]
REGEX = (matchjust)apartofaword
FORMAT = myotherfield::$1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If any of these apply to your extraction, you are very likely seeing the effects that the blog post I linked to talks about.&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2013 06:12:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Cannot-search-customized-field/m-p/30706#M6247</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-05-13T06:12:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot search customized field ...</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Cannot-search-customized-field/m-p/30707#M6248</link>
      <description>&lt;P&gt;Thank you, Ayn.&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2013 02:44:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Cannot-search-customized-field/m-p/30707#M6248</guid>
      <dc:creator>sunrise</dc:creator>
      <dc:date>2013-05-15T02:44:47Z</dc:date>
    </item>
  </channel>
</rss>

