Splunk Enterprise

Why the key field is missing from the KVStore

splunkrocks2014
Communicator

I defined a custom key field for my KVStore and have a savedsearch loads contents to all fields (include key); however, when checking the data, the key field is missing from the KVStore. Any clues?

Tags (1)
0 Karma

elliotproebstel
Champion

The key won't display by default. If I want to view the key field, I add this to a search:

| eval key=_key

This will make it visible in tables/stats/etc.

Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...