Splunk Search

Interesting fields generated from the AWS Add-On not showing up in Search&Reporting App?

mcirrici
Explorer

Hi,

I have a CloudTrail data source feeding into the AWS Add-On app on a single-instance Splunk deployment.

If I go to the AWS app and do a search from within that app, Splunk is able to extract all the interesting fields and populate them into key-vaule pairs just fine.

However, I've built a dashboard using that data source and interesting fields in the S&R app and Splunk does not populate those same key-vaule pairs as it would in the AWS app.

The only way to extract those key-vaule pairs from within the S&R app is to do a 'spath' search which is not the best way to build the searches in the dashboard.

I've already checked the fields settings and it's showing all the AWS fields enabled globally in the permissions section.

Has anybody experienced this issue before, or have any ideas where to poke at to get the fields to be extracted globally?

Labels (1)
0 Karma

dannyrm
Engager

Hi, 

Were you able to figure out what was causing this issue? I am experiencing the same problem within my environment. 

0 Karma
Get Updates on the Splunk Community!

Celebrating Fast Lane: 2025 Authorized Learning Partner of the Year

At .conf25, Splunk proudly recognized Fast Lane as the 2025 Authorized Learning Partner of the Year. This ...

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...