Dashboards & Visualizations

Why is there Splunk warning message: [indexer-name] field does not exist in data?

neerajs_81
Builder

Hi All,
we are on Splunk cloud. On one of our dashboard panels,  I am getting a warning message: [idx-xxxx field 'technique_id' does not exist in the data] 
Interestingly this wasn't the case until last week.  Pls see below screenshots.  The search runs by default in Fast mode as its a dashboard query. It populates data in a panel.  While troubleshooting, if  i run it manually in verbose mode, the field technique_id exists under "Interesting fields".  Why is fast mode throwing that warning and how to get rid of it?   Is this an indexing issue with one of those indexers?

neerajs_81_0-1691408218203.png

neerajs_81_1-1691408369515.png

 

 

 

Labels (3)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...