Getting Data In

SELECTED FIELDS

fridays
Explorer

How to add fields to "selected fields" from the event. Some fields, such as name and sc_pl, are missing in the selected fields.
alt text

Tags (1)
0 Karma

fridays
Explorer

no fields.alt text

0 Karma

fridays
Explorer

This is All Fields. In splunk 6.5 all fields were in place. The problem appeared after the update on the splank 7.2.4

alt text

0 Karma

MoniM
Communicator

I am not sure if this will work for you or not. You can try by deleting the Field Aliases.

Below is the answer for the same issue:-
https://answers.splunk.com/answers/693737/splunk-720-field-aliases-incorrect-behavior.html

0 Karma

fridays
Explorer

In screensot select All fields. And no filters

0 Karma

nikita_p
Contributor

Hi Fridays,
How are you searching your fields?
If you want to see all selected fields you need to search it in verbose mode and also make sure the coverage selected is "All Fields"

0 Karma

MoniM
Communicator

Hi @fridays ,
One of the reason for this is the coverage percentage.
please find below snap for the setting in your "All Fields tab".alt text

woodcock
Esteemed Legend

Click on the All Fields link in the left-most panel under the histogram. Any field that has a checkmark will be a SELECTED FIELD.

0 Karma

fridays
Explorer

"All fields" - do not include all fields.alt text No serv, name and other fields.

0 Karma

woodcock
Esteemed Legend

It is relatively dynamic and will only show those fields that exist in your current search results. To get those other fields available, run a search that returns results with those fields (or just do something like | eval serv = "foo".

0 Karma

MoniM
Communicator

Hi fridays,
you can go to "All Fields" and from there you can select the required fields of your interest(check the box for the field you want).

Hope it helps!
Thanks

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

(re)Introducing the Splunk Community Champions + 2026 – 2027 Splunk MVPs ...

This program exists as a channel to empower and recognize Splunk advocates and help supercharge initiatives to ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Pro Tips for .conf26: How to Prep Like a Splunk Veteran

There’s no shortage of incredible content lined up for .conf26 in Denver, from deep-dive technical sessions ...