Seem to have an issue with the ELB - Traffic Analysis Dashboard on the Splunk App for AWS - only two ELBs show up when the search runs .
Any ideas what the issue might be ? Any ideas why the elb field is missing for the other inputs ? All of them ( 12 in total ) are configured the same way .
Found the solution - had to "manually" extract the fields - for some reason the Regex within props.conf did not work 😞
Are you using splunkcloud?
Regards,
Arsenio
Arsenio ,
I am using Splunk Enterprise . Turns out the Filed Extracts were not correctly extracting the field "elb" ( amongst others )
Rewriting the regex in props.conf fixed this issue
Found the solution - had to "manually" extract the fields - for some reason the Regex within props.conf did not work 😞