Splunk Search

Field Extracted not There

skoelpin
SplunkTrust
SplunkTrust

I did four field extractions for the same thing and can't find them anywhere. After logging back in this morning I was able to see one of them in the field section on the left. All extractions are in the same index and have them same source and sourcetype. When going to Settings/Fields/Field extractions I can see all 4 extractions but I cannot see them at search time.

Does this have something to do with what I was searching when doing the initial extraction? Also the one that is visible now is only visible when I looking for a certain web service call.

0 Karma

woodcock
Esteemed Legend

Is this actually a Search Head cluster behind a VIP where the synchronization is not working? This has bitten me several times.

0 Karma

woodcock
Esteemed Legend

Click "verbose mode" under the TimePicker in the upper-right.

skoelpin
SplunkTrust
SplunkTrust

Yeah I tried that along with inspecting all the fields and it is not there. I went into Settings>Field Extractions and I can see my fields there but only one of them is showing up now. They all have global permissions. There was another field which I was using yesterday and it's gone too! I also tried plugging it into the search with a * and it comes back as no results found. Do you think it will come back up if I restart the Splunk server? I try to keep restarts to a minimum as 20 other people are using it at any given time

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...