Splunk Search

How to get indexed fields filtered by the fields command?

akazarov
Path Finder

Hello,

When indexing data, I extract some selected fields. Thus, these fields are not part of 'EXTRACT-fields' line in props.conf, as it is suggested by documentation. Fields are indexed fine and I can search using the fields names. However, what does not work is extracting some of these fields from the search using the | fields command, like:

index=.. <search criteria> | fields gh

I do see these fields in Splunk Web, and for example | table gh works with the fields, but not the | fields which produces no results.
Puzzled. Is there a special syntax to refer to indexed fields in the fields filter?

Thanks
Andrei

0 Karma

woodcock
Esteemed Legend

If things are exactly as you say then there is a bug and you should open a case on this. In the meantime, try this as a work around:

... | table * _* | fields gh

When I have seen this bug before (v4.?) I could pass through table first to make it work.

0 Karma
Get Updates on the Splunk Community!

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

Cisco Use Cases, ITSI Best Practices, and More New Articles from Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...