Splunk Search

Fields have disappeared

kmattern
Builder

I had a log file that I generated fields for and it worked fine. The log file was not updated for two weeks. When it was updated today the fields have vanished. If I search and use all time I can see the fields but If I search just for today the fields have vanished. Any thoughts or suggestions?

A typical record looks like this

6/23/2010,8:22:51,Account_Name,5,5

The fields are

Date, Time, Account, Received, Authorized

Tags (1)
0 Karma

Simeon
Splunk Employee
Splunk Employee

You should post exact events from before and after. Please also post the extraction. Otherwise, it will be difficult to figure out why they have disappeared.

Simeon
Splunk Employee
Splunk Employee

This can happen if something has changed within the event format or the source/sourcetype has changed. The extractions get applied based on the type of input and then a regex is applied to each event for field extraction. If your new data has a different format it is likely that the field extraction is not working correctly.

blebit
Path Finder

Hi Simeon,
My problem is as you explain. i have modified sourcetypes of ironport (thats because i want to separate access logs from config logs, cli logs, etc). before i had fields like c_ip, cs_username and so on. now these fields are disappeared.
How can i fix this ?

Thanks

0 Karma

Lowell
Super Champion

Please add some additional details to your question (use the "edit" link). Specifically, how did you add the fields? Are you running as the same splunk user as you were previously? (Could be permissions related). Are you sure you simply don't have the fields selected to be shown. Are you searching from a different application than before?

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...