Splunk Search

Adding a new indexed meta field to inputs.conf not showing up in fastmode

brent_weaver
Builder

We see it in smart mode but not in fast mode. What are we missing and where does this get defined?

0 Karma

Sukisen1981
Champion

if you can see it in both search and verbose mode, then one check that I suggest in do you know for sure that the custom meta field (i am assuming this is indexed filed and not a default field) occurs for greater than 20% of the events? To test you can change your inputs.conf and slightly re-configure the meta field to have it display for all fields like for source or sourcetype.

0 Karma

Sukisen1981
Champion
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...