Splunk Search

Fields have disappeared

kmattern
Builder

I had a log file that I generated fields for and it worked fine. The log file was not updated for two weeks. When it was updated today the fields have vanished. If I search and use all time I can see the fields but If I search just for today the fields have vanished. Any thoughts or suggestions?

A typical record looks like this

6/23/2010,8:22:51,Account_Name,5,5

The fields are

Date, Time, Account, Received, Authorized

Tags (1)
0 Karma

Simeon
Splunk Employee
Splunk Employee

You should post exact events from before and after. Please also post the extraction. Otherwise, it will be difficult to figure out why they have disappeared.

Simeon
Splunk Employee
Splunk Employee

This can happen if something has changed within the event format or the source/sourcetype has changed. The extractions get applied based on the type of input and then a regex is applied to each event for field extraction. If your new data has a different format it is likely that the field extraction is not working correctly.

blebit
Path Finder

Hi Simeon,
My problem is as you explain. i have modified sourcetypes of ironport (thats because i want to separate access logs from config logs, cli logs, etc). before i had fields like c_ip, cs_username and so on. now these fields are disappeared.
How can i fix this ?

Thanks

0 Karma

Lowell
Super Champion

Please add some additional details to your question (use the "edit" link). Specifically, how did you add the fields? Are you running as the same splunk user as you were previously? (Could be permissions related). Are you sure you simply don't have the fields selected to be shown. Are you searching from a different application than before?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...