Splunk Search

Field Extracted not There

skoelpin
SplunkTrust
SplunkTrust

I did four field extractions for the same thing and can't find them anywhere. After logging back in this morning I was able to see one of them in the field section on the left. All extractions are in the same index and have them same source and sourcetype. When going to Settings/Fields/Field extractions I can see all 4 extractions but I cannot see them at search time.

Does this have something to do with what I was searching when doing the initial extraction? Also the one that is visible now is only visible when I looking for a certain web service call.

0 Karma

woodcock
Esteemed Legend

Is this actually a Search Head cluster behind a VIP where the synchronization is not working? This has bitten me several times.

0 Karma

woodcock
Esteemed Legend

Click "verbose mode" under the TimePicker in the upper-right.

skoelpin
SplunkTrust
SplunkTrust

Yeah I tried that along with inspecting all the fields and it is not there. I went into Settings>Field Extractions and I can see my fields there but only one of them is showing up now. They all have global permissions. There was another field which I was using yesterday and it's gone too! I also tried plugging it into the search with a * and it comes back as no results found. Do you think it will come back up if I restart the Splunk server? I try to keep restarts to a minimum as 20 other people are using it at any given time

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...