Dashboards & Visualizations

site value not populating correctley

Ram2
Explorer

We have a query where we are  getting the count by site.

index=test-index |stats count by host site.

When we run this query in search head cluster we are getting output as 

site                       host

undefined         appdtz

undefined        appstd

undefined        apprtg

undefined        appthf

 

When we run the same query in deployer we are getting output correctly with site.

site                       host

sitea         appdtz

sitea       appstd

siteb        apprtg

siteb        appthf

 how to fix this issue in SH cluster.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Ram2 ,

probaby you runned the search on SHC outside the app where the site fied is extracted.

have you in the events the site field?

Ciao.

Giuseppe

0 Karma

Ram2
Explorer

Hi @gcusello ,

probaby you runned the search on SHC outside the app where the site fied is extracted. --No i am running the same query under search and reporting app  in SHC and Deployer

have you in the events the site field? --No these are default values for a host coming from universal forwarder,  what they set from application side.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Ram2 ,

what's the Mode you're using? you must use Verbose.

if the site field isn't extracted, you cannoy use it, did you extracted the site field?

Ciao.

Giuseppe

0 Karma

Ram2
Explorer

@gcusello ,

what's the Mode you're using? you must use Verbose. --running in verbose mode.

if the site field isn't extracted, you cannoy use it, did you extracted the site field? -- The site field is a default field like host sourcetype. 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Ram2 ,

host e sourcetype are indextime fields that you associate to your data surce, site should be an extracted field.

Have you this field running only the search without stats?

if not (as probable) you have to extract it.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...