Splunk Search

I defined a field extraction, but why is the field not getting listed under interesting fields on the search results page?



I am facing issues with the use of extracted fields.
I intend to create a timechart with the extracted values. I have created new field on the field extraction page and gave the right permissions. Still the field is not showing up in the list of interesting fields on the search page. Is there any additional step that I am missing?

I do not have access to props.conf file.
Please suggest the way forward. Any help is much appreciated.


0 Karma

New Member

I am facing same problem, I am able to see the field in settings> fields > extracted fields. but not under interested fields, I have selected the correct sourcetype but still am unable to see the extracted field under interested fields.

0 Karma


The extracted field is relative to the sourcetype that you chose when extracting that field. So make sure you have the correct sourcetype then flip your search mode in smart or verbose mode then you should see it. You can also select "all Fields" and find your new field and check the box and it will show in your 'Selected Fields' section


Check you search mode. Interesting fields do not display in Fast mode. Should be Smart or Verbose. Interesting fields show up only if more than 20% of the events have that field. Try using it in a command. Something like stats count by field


 have this same problem with Splunk 8.2.

If I search as:
index=index_name | stats count by field_name
I do have the result by field_name

If I search as:

I cannot find anywhere the field_name on the fields list. Even when searching in Verbose Mode and when going to "Select Fields" and choosing "All Fields" option -  still field_name is nowhere to be found.

I have noticed this problem previously in Splunk 6 and 7 too

0 Karma


Thanks so much Sundareshr!
This info was quite handy.

0 Karma
Get Updates on the Splunk Community!

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

Observability Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestSplunk APM's New Tag Filter ExperienceSplunk APM has updated ...

Security Newsletter Updates | March 2023

 March 2023 | Check out the latest and greatestUnify Your Security Operations with Splunk Mission Control The ...