Dashboards & Visualizations

Extracted fields are not shown in dashboards or scheduled reports

asnegina
New Member

I have some extracted fields and I do see them while searching. In smart mode I select interesting fields and hit "Save as report", everything is OK:
alt text

But when I schedule this report and it runs, my fields don't show up! I can see only _time left in this scheduled report:

alt text

And if I hit "Open in Search..." my extracted fields are here again.
Same thing when trying to save my search as s dashboard pane: no extracted fields, even if using "fields" command.
All permissions on extracted fields are Global: I checked twice. This is a demo instance, so I use only one user for creating fields and reports.
What am I missing? Any privacy settings?

0 Karma
1 Solution

peterchenadded
Path Finder

Can you please send through your query.

You might want to add

Your base search | table _time, ru_event_type, description, sender, atom

To see if it helps.

View solution in original post

0 Karma

peterchenadded
Path Finder

Can you please send through your query.

You might want to add

Your base search | table _time, ru_event_type, description, sender, atom

To see if it helps.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...