Hi All,
we are on Splunk cloud. On one of our dashboard panels, I am getting a warning message: [idx-xxxx field 'technique_id' does not exist in the data]
Interestingly this wasn't the case until last week. Pls see below screenshots. The search runs by default in Fast mode as its a dashboard query. It populates data in a panel. While troubleshooting, if i run it manually in verbose mode, the field technique_id exists under "Interesting fields". Why is fast mode throwing that warning and how to get rid of it? Is this an indexing issue with one of those indexers?