All Apps and Add-ons

After updating Splunk and the Splunk Add-on for Juniper, why is the src field no longer listed for Juniper logs?


After updating to Splunk 7.2 and updating the Splunk Add-on for Juniper a few weeks ago, I noticed that the 'src' field is no longer listed even though it's still a field extraction and checking to see if perhaps it wasn't a field that was selected, but even in that screen the only field showing is src_port.

When I click 'Extract new fields' the value for the event selected shows src being an existing extracted field and when I open that field extraction, it does have the K/V info for src extracted.

Any ideas?

Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...