Splunk Search

Problem with extracted field

ChhayaV
Communicator

Hi,

I am not able to see extracted fields in "Interesting field list",however fields are visible in Manager.
What can be the problem ?

Thanks and Regards

Tags (1)
0 Karma

dmlee
Communicator

below are my suggestion :
1st, check the permission and app of the field you defined , you must be in the same app as the field belongs to ( if you share to "App" but not to "global" )
2nd, click the "edit" icon on the upper right corner of "Interesting field list" , you can see all fields list
3rd, if you cannot find specific field that you defined before , may be the reason is there is no matched rule in your search result

0 Karma

ChhayaV
Communicator

hi, 1st I have kept permisisons for all the extracted fields as global
2nd Its not showing extractes fields
3rd Its matching because i can use those fields in my query its working. i am not able to see it in "Interesting field list"

0 Karma

kristian_kolb
Ultra Champion

My guess is that either;

a) the regex for extracting the field is not matching any event in your search results. This is then the expected behaviour. The definition will always be visible in manager, but if no event matches the regex, then the field name will not show in the search app, as the field is not present in the events. Or perhaps your extraction regex is wrong and needs to be edited.

b) your field name contains a hyphen (dash/minus/-). That used to be a problem when you created fields, but maybe that has been fixed by now. If you created your field extraction through IFX, you didn't get an error message. Normally fields names shall only contain letters, numbers and underscores, and must start with a letter. If that is the issue, change the name of the field. (most likely in props.conf).

Hope this helps,

/K

0 Karma

ChhayaV
Communicator

regex is proper i am able to use the fileds in query and i have given simple string names its not containing hyphen

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...