All Apps and Add-ons

Universal Field Extractor: Why is the app not displaying all sources?

timm747747
Path Finder

When I select the "source" dropdown in the Universal Field Extractor app, it doesn't display all of the sources associated with the index I've restricted the extraction to. I tried to look at the code, but it's Python and 1280 lines worth of code that I didn't feel comfortable messing with. I assume the search may only be going back 5 minutes or 15 minutes or something and not doing a complete search of all available results, just to finish quickly.

Any ideas?

Thanks!

0 Karma

woodcock
Esteemed Legend
0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...