Hi @Jasmine,
"app" and "servie" are not default Splunk fields, although they may be extracted in your search context.
If you're using the search interface to explore data, make sure you're running searches in "Smart Mode" (preferably) or "Verbose Mode." The mode selector is just below the magnifying glass search button.
Hi @Jasmine .. We may need more details from you.
Please update us your current Splunk Search query (remove any hostnames, ip address, etc before posting it here)