Dashboards & Visualizations

Why can I not produce table even when fields exist in events

POR160893
Builder

Hi,

I am trying to create a table of top N categories per Region for a number of indexes. However, when I run the query on some indexes, the necessary fields exist in the events, i.e. category, region, NodeName, host, .... yet, no table is produced in the statistics.

The Statistics is as follows:

POR160893_0-1648119108765.png

And here are the respective events with necessary fields:

POR160893_1-1648119153642.png

 



Why would that be?



Thanks,
Patrick

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @POR160893,

whick one of your two indexes has the problem?

identify it and then debug this index, maybe the extraction is a little different than the other.

Could you share a sample of both indexes containing the same category?

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...