Splunk Search

How to get indexed fields filtered by the fields command?

akazarov
Path Finder

Hello,

When indexing data, I extract some selected fields. Thus, these fields are not part of 'EXTRACT-fields' line in props.conf, as it is suggested by documentation. Fields are indexed fine and I can search using the fields names. However, what does not work is extracting some of these fields from the search using the | fields command, like:

index=.. <search criteria> | fields gh

I do see these fields in Splunk Web, and for example | table gh works with the fields, but not the | fields which produces no results.
Puzzled. Is there a special syntax to refer to indexed fields in the fields filter?

Thanks
Andrei

0 Karma

woodcock
Esteemed Legend

If things are exactly as you say then there is a bug and you should open a case on this. In the meantime, try this as a work around:

... | table * _* | fields gh

When I have seen this bug before (v4.?) I could pass through table first to make it work.

0 Karma
Get Updates on the Splunk Community!

Splunk Lantern | Getting Started with Edge Processor, Machine Learning Toolkit ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...