Splunk Search

Httpevent collector logs in to splunk, not showing the host,source,sourcetype in splunk

vijreddy30
Loves-to-Learn Everything

 

Hi All,

Httpevent collector logs in to splunk, not showing the host,source,sourcetype in splunk, please find the below screen shot, please help me.

 

vijreddy30_0-1723209320043.png

 

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

That doesn't seem right. Those fields should not be empty so something must be overwriting it in search-time (or your indexes are damaged but let's assume they aren't).

Try

| tstats count where index=dfini by source sourcetype host

That should show you what are the indexed fields.

You have to search your search-time definitions to see what overwrites those values.

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...