Splunk Search

Interesting fields generated from the AWS Add-On not showing up in Search&Reporting App?

mcirrici
Explorer

Hi,

I have a CloudTrail data source feeding into the AWS Add-On app on a single-instance Splunk deployment.

If I go to the AWS app and do a search from within that app, Splunk is able to extract all the interesting fields and populate them into key-vaule pairs just fine.

However, I've built a dashboard using that data source and interesting fields in the S&R app and Splunk does not populate those same key-vaule pairs as it would in the AWS app.

The only way to extract those key-vaule pairs from within the S&R app is to do a 'spath' search which is not the best way to build the searches in the dashboard.

I've already checked the fields settings and it's showing all the AWS fields enabled globally in the permissions section.

Has anybody experienced this issue before, or have any ideas where to poke at to get the fields to be extracted globally?

Labels (1)
0 Karma

dannyrm
Engager

Hi, 

Were you able to figure out what was causing this issue? I am experiencing the same problem within my environment. 

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...