Seem to have an issue with the ELB - Traffic Analysis Dashboard on the Splunk App for AWS - only two ELBs show up when the search runs .
Any ideas what the issue might be ? Any ideas why the elb field is missing for the other inputs ? All of them ( 12 in total ) are configured the same way .
I am using Splunk Enterprise . Turns out the Filed Extracts were not correctly extracting the field "elb" ( amongst others )
Rewriting the regex in props.conf fixed this issue