Splunk Search

Interesting fields generated from the AWS Add-On not showing up in Search&Reporting App?

mcirrici
Explorer

Hi,

I have a CloudTrail data source feeding into the AWS Add-On app on a single-instance Splunk deployment.

If I go to the AWS app and do a search from within that app, Splunk is able to extract all the interesting fields and populate them into key-vaule pairs just fine.

However, I've built a dashboard using that data source and interesting fields in the S&R app and Splunk does not populate those same key-vaule pairs as it would in the AWS app.

The only way to extract those key-vaule pairs from within the S&R app is to do a 'spath' search which is not the best way to build the searches in the dashboard.

I've already checked the fields settings and it's showing all the AWS fields enabled globally in the permissions section.

Has anybody experienced this issue before, or have any ideas where to poke at to get the fields to be extracted globally?

Labels (1)
0 Karma

dannyrm
Engager

Hi, 

Were you able to figure out what was causing this issue? I am experiencing the same problem within my environment. 

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...