Splunk Search

Fields have disappeared

kmattern
Builder

I had a log file that I generated fields for and it worked fine. The log file was not updated for two weeks. When it was updated today the fields have vanished. If I search and use all time I can see the fields but If I search just for today the fields have vanished. Any thoughts or suggestions?

A typical record looks like this

6/23/2010,8:22:51,Account_Name,5,5

The fields are

Date, Time, Account, Received, Authorized

Tags (1)
0 Karma

Simeon
Splunk Employee
Splunk Employee

You should post exact events from before and after. Please also post the extraction. Otherwise, it will be difficult to figure out why they have disappeared.

Simeon
Splunk Employee
Splunk Employee

This can happen if something has changed within the event format or the source/sourcetype has changed. The extractions get applied based on the type of input and then a regex is applied to each event for field extraction. If your new data has a different format it is likely that the field extraction is not working correctly.

blebit
Path Finder

Hi Simeon,
My problem is as you explain. i have modified sourcetypes of ironport (thats because i want to separate access logs from config logs, cli logs, etc). before i had fields like c_ip, cs_username and so on. now these fields are disappeared.
How can i fix this ?

Thanks

0 Karma

Lowell
Super Champion

Please add some additional details to your question (use the "edit" link). Specifically, how did you add the fields? Are you running as the same splunk user as you were previously? (Could be permissions related). Are you sure you simply don't have the fields selected to be shown. Are you searching from a different application than before?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...