<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why am I missing all &amp;quot;Interesting Fields&amp;quot; in the Search &amp; Reporting screen? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-missing-all-quot-Interesting-Fields-quot-in-the-Search/m-p/227239#M67118</link>
    <description>&lt;P&gt;Interesting fields only show up if there more that 20% of the events with that field. Having said that, what mode is your search set to? Interesting fields will not show in Fast mode. Try changing it to Smart or Verbose&lt;/P&gt;</description>
    <pubDate>Fri, 13 Nov 2015 17:27:51 GMT</pubDate>
    <dc:creator>sundareshr</dc:creator>
    <dc:date>2015-11-13T17:27:51Z</dc:date>
    <item>
      <title>Why am I missing all "Interesting Fields" in the Search &amp; Reporting screen?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-missing-all-quot-Interesting-Fields-quot-in-the-Search/m-p/227238#M67117</link>
      <description>&lt;P&gt;I'm missing ALL of the interesting fields.  &lt;/P&gt;

&lt;P&gt;I used to see such things as date_hour, date_minute, etc, etc.  If I manually add those to the search, they show up in "Interesting Fields". &lt;BR /&gt;
Same with my custom fields in &lt;CODE&gt;splunk/etc/apps/search/local/props.conf&lt;/CODE&gt;.  If I add them to the search, they'll show up under "Interesting Fields".  &lt;/P&gt;

&lt;P&gt;If I go to "Extract New Fields", and click on a line, they show up as already defined.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 07:52:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-missing-all-quot-Interesting-Fields-quot-in-the-Search/m-p/227238#M67117</guid>
      <dc:creator>ajscam</dc:creator>
      <dc:date>2020-09-29T07:52:09Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I missing all "Interesting Fields" in the Search &amp; Reporting screen?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-missing-all-quot-Interesting-Fields-quot-in-the-Search/m-p/227239#M67118</link>
      <description>&lt;P&gt;Interesting fields only show up if there more that 20% of the events with that field. Having said that, what mode is your search set to? Interesting fields will not show in Fast mode. Try changing it to Smart or Verbose&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2015 17:27:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-missing-all-quot-Interesting-Fields-quot-in-the-Search/m-p/227239#M67118</guid>
      <dc:creator>sundareshr</dc:creator>
      <dc:date>2015-11-13T17:27:51Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I missing all "Interesting Fields" in the Search &amp; Reporting screen?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-missing-all-quot-Interesting-Fields-quot-in-the-Search/m-p/227240#M67119</link>
      <description>&lt;P&gt;what a freaking life saver. i was on fast mode&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:10:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-missing-all-quot-Interesting-Fields-quot-in-the-Search/m-p/227240#M67119</guid>
      <dc:creator>morethanyell</dc:creator>
      <dc:date>2020-02-21T07:10:46Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I missing all "Interesting Fields" in the Search &amp; Reporting screen?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-missing-all-quot-Interesting-Fields-quot-in-the-Search/m-p/585611#M204037</link>
      <description>&lt;P class="lia-align-left"&gt;thank you. i was on fast mode too.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Feb 2022 17:32:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-missing-all-quot-Interesting-Fields-quot-in-the-Search/m-p/585611#M204037</guid>
      <dc:creator>metennisman1988</dc:creator>
      <dc:date>2022-02-17T17:32:35Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I missing all "Interesting Fields" in the Search &amp; Reporting screen?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-missing-all-quot-Interesting-Fields-quot-in-the-Search/m-p/585619#M204038</link>
      <description>&lt;P&gt;One way to see those even in fast mode is add “| fields *” after your 1st part. Is it wise or not is another story….&lt;/P&gt;</description>
      <pubDate>Thu, 17 Feb 2022 18:07:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-missing-all-quot-Interesting-Fields-quot-in-the-Search/m-p/585619#M204038</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-02-17T18:07:16Z</dc:date>
    </item>
  </channel>
</rss>

