I faced the same issue. The problem is with the "source" key in the input json. Replace it with something like "data". Then Splunk recognizes all fields.,I have the same problem. The issue is with key "source" in the input json. Replace it with some else for example: "data". Then you see all the fields inside data subjson.