Hi All,
One of my fields summary in Splunk field bar is not showing 100 percent, even though I have that field in all events. This field is under selected fields as well.
When I specifically make this field in a search or click on "Events with this field", then only I get 100 percent values
Why it is not 100 percent in the first case?
1) Are you saying that the exact name of the field is summary
? It could be that you are running into problems due to naming a field with a commonly reserved word.
2) use earliest="04/25/2017:23:00:00" latest="04/27/2017:01:00:00"
(or any such values) and narrow the time range of the search until you get a dozen records or so, where less than 100% are detected as having the field. Then you can look at individual records and see if the field is present and if there is a pattern.
It could be that the fields is not extracted/recognized by Splunk for some events. Try to run this query to find out events where Splunk is not able to recognize it and verify the raw data.
your base search Yourfield!=*
Hi Somesoni2,
I have already that and it gives me no results which means all my events have that field. I have already mentioned that in my question.
Without knowing how your data looks like, etc it's hard to say but if I were you I would try to identify those events where the field is not present. You can do this by using the following syntax:
index=yourindex sourcetype=yoursourcetype NOT fieldname=*
I have already tried the query above and it gives me no events which means the field is present in all of my events.
Field 'subtype' has 6 values, 6.442% events. But that field is present is all my events. I confirm this if i click on Events with this field and it gives me same number of events. It look like below
subtype
Selected Yes No
6 Values, 7.563% of events
Reports
Top values Top values by time Rare values
Events with this field
I've got the same question. There's a field that should be 100% but Splunk is reporting some extremely low percentage. Something else is going on that is not evident -- maybe the percentage means something else. If so, no idea. Filed a support case for answers.
Which mode are you running the search in, fast or smart? This field, should it be auto extracted or there is a custom field extraction setup for it?