After updating to Splunk 7.2 and updating the Splunk Add-on for Juniper a few weeks ago, I noticed that the 'src' field is no longer listed even though it's still a field extraction and checking to see if perhaps it wasn't a field that was selected, but even in that screen the only field showing is src_port.
When I click 'Extract new fields' the value for the event selected shows src being an existing extracted field and when I open that field extraction, it does have the K/V info for src extracted.
Any ideas?