Knowledge Management

Stash logs

sara
New Member

 we are unable to create further detections in ES because some key fields are missing in the stash logs. After reviewing the source logs, I found that the entity fields are marked as    unknown.

We have been informed that these are internal logs, so raising a support case is not an option.

How can we identify the root cause of the missing data and determine why these fields are not being populated?

Labels (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @sara 

Can you provide an exampe of the events which are missing fields?

Splunk Support will still usually assist where they can with issues like this if the data is being generated by your Splunk deployment, if the events missing fields are coming from outside of Splunk then I imagine we wont be able to help too much but if its generated within Splunk then support should help.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

PickleRick
SplunkTrust
SplunkTrust

What stash logs? What source logs?

Are you trying to run your detections on some summarized data?

What internal logs are you talking about?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...