Splunk Search

Fieldset disappears when using table command

JoeSco27
Communicator

I have recently upgraded from 4.3 to the latest 5.x version. I found that now when I use the table command the fieldset on the left hand side disappears and I cant click on the selector to go from tableView to the raw log events. I frequently use a macro that puts the fields into a table by the headers I have chosen, and I get value out of this because I can use the fieldset to narrow the search. Is this a bug or is there a way around this for 5.X

Thank you.

Tags (3)
0 Karma
1 Solution

alacercogitatus
SplunkTrust
SplunkTrust

alacercogitatus
SplunkTrust
SplunkTrust

You will want to change the "Smart Mode" to "Verbose Mode".

http://docs.splunk.com/Documentation/Splunk/5.0.5/Search/Changethesearchmode

JoeSco27
Communicator

Thank you!

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...