Splunk Search

Interesting fields generated from the AWS Add-On not showing up in Search&Reporting App?

mcirrici
Explorer

Hi,

I have a CloudTrail data source feeding into the AWS Add-On app on a single-instance Splunk deployment.

If I go to the AWS app and do a search from within that app, Splunk is able to extract all the interesting fields and populate them into key-vaule pairs just fine.

However, I've built a dashboard using that data source and interesting fields in the S&R app and Splunk does not populate those same key-vaule pairs as it would in the AWS app.

The only way to extract those key-vaule pairs from within the S&R app is to do a 'spath' search which is not the best way to build the searches in the dashboard.

I've already checked the fields settings and it's showing all the AWS fields enabled globally in the permissions section.

Has anybody experienced this issue before, or have any ideas where to poke at to get the fields to be extracted globally?

Labels (1)
0 Karma

dannyrm
Engager

Hi, 

Were you able to figure out what was causing this issue? I am experiencing the same problem within my environment. 

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...