All Apps and Add-ons

Splunk Add-on for Microsoft Windows: Why are several Windows log fields missing from "Selected Fields"?

yelloworb
New Member

I have a single Splunk light search head. I noticed EventCode and other windows log fields are missing from "Selected Fields."

So I enabled Splunk Add-on for Microsoft Windows. Still not shown.
All fields show are;
host, index, linecount, source, sourcetype, and splunk_server.

Do I need further configuration?

0 Karma
1 Solution

Richfez
SplunkTrust
SplunkTrust

I suspect you are displaying results in 'Fast' mode, which doesn't do all the work to find/display the fields like that. You can change it by a drop-down under your "Time" dropdown. It probably says 'Fast' or 'Smart' (where mine in the below example already showed 'Verbose Mode'.)

Smart, Fast or Verbose mode

You will want to pick "Verbose" then rerun your search.

You may be interested in a free e-learning course from Splunk: the Splunk Tutorial. I'm not positive it covers fast vs. verbose mode, but it has lots of useful "getting started" nuggets in it.

View solution in original post

0 Karma

Richfez
SplunkTrust
SplunkTrust

I suspect you are displaying results in 'Fast' mode, which doesn't do all the work to find/display the fields like that. You can change it by a drop-down under your "Time" dropdown. It probably says 'Fast' or 'Smart' (where mine in the below example already showed 'Verbose Mode'.)

Smart, Fast or Verbose mode

You will want to pick "Verbose" then rerun your search.

You may be interested in a free e-learning course from Splunk: the Splunk Tutorial. I'm not positive it covers fast vs. verbose mode, but it has lots of useful "getting started" nuggets in it.

0 Karma

yelloworb
New Member

Thank you so much for your answer. I started the Tutorial you mentioned, which is very helpful! It did refer to the "verbose Mode," hinted for more fields.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...