Splunk Enterprise

Why the key field is missing from the KVStore

splunkrocks2014
Communicator

I defined a custom key field for my KVStore and have a savedsearch loads contents to all fields (include key); however, when checking the data, the key field is missing from the KVStore. Any clues?

Tags (1)
0 Karma

elliotproebstel
Champion

The key won't display by default. If I want to view the key field, I add this to a search:

| eval key=_key

This will make it visible in tables/stats/etc.

Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...