Splunk Search

Only the raw field has data.rest everything and every field is empty

vishtrip
New Member

I have an issue where the raw data shows up with data but when I query it, all the other fields come up as empty. 

 

I have used a simple query"

index = syslogs "10.250.0.136" | table SYSLOG_message,SYSLOG_mne,_time,_raw

Labels (1)
0 Karma

vishtrip
New Member

Below is what the raw field has:

2020-09-01T02:18:01+00:00 10.250.0.136 lemd[34] ERROR GET 11522622 from <ip address>:48053 failed 500 <device name> 0
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...