Splunk Search

Field Extracted not There

skoelpin
SplunkTrust
SplunkTrust

I did four field extractions for the same thing and can't find them anywhere. After logging back in this morning I was able to see one of them in the field section on the left. All extractions are in the same index and have them same source and sourcetype. When going to Settings/Fields/Field extractions I can see all 4 extractions but I cannot see them at search time.

Does this have something to do with what I was searching when doing the initial extraction? Also the one that is visible now is only visible when I looking for a certain web service call.

0 Karma

woodcock
Esteemed Legend

Is this actually a Search Head cluster behind a VIP where the synchronization is not working? This has bitten me several times.

0 Karma

woodcock
Esteemed Legend

Click "verbose mode" under the TimePicker in the upper-right.

skoelpin
SplunkTrust
SplunkTrust

Yeah I tried that along with inspecting all the fields and it is not there. I went into Settings>Field Extractions and I can see my fields there but only one of them is showing up now. They all have global permissions. There was another field which I was using yesterday and it's gone too! I also tried plugging it into the search with a * and it comes back as no results found. Do you think it will come back up if I restart the Splunk server? I try to keep restarts to a minimum as 20 other people are using it at any given time

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...