Splunk Search

Problem with extracted field

ChhayaV
Communicator

Hi,

I am not able to see extracted fields in "Interesting field list",however fields are visible in Manager.
What can be the problem ?

Thanks and Regards

Tags (1)
0 Karma

dmlee
Communicator

below are my suggestion :
1st, check the permission and app of the field you defined , you must be in the same app as the field belongs to ( if you share to "App" but not to "global" )
2nd, click the "edit" icon on the upper right corner of "Interesting field list" , you can see all fields list
3rd, if you cannot find specific field that you defined before , may be the reason is there is no matched rule in your search result

0 Karma

ChhayaV
Communicator

hi, 1st I have kept permisisons for all the extracted fields as global
2nd Its not showing extractes fields
3rd Its matching because i can use those fields in my query its working. i am not able to see it in "Interesting field list"

0 Karma

kristian_kolb
Ultra Champion

My guess is that either;

a) the regex for extracting the field is not matching any event in your search results. This is then the expected behaviour. The definition will always be visible in manager, but if no event matches the regex, then the field name will not show in the search app, as the field is not present in the events. Or perhaps your extraction regex is wrong and needs to be edited.

b) your field name contains a hyphen (dash/minus/-). That used to be a problem when you created fields, but maybe that has been fixed by now. If you created your field extraction through IFX, you didn't get an error message. Normally fields names shall only contain letters, numbers and underscores, and must start with a letter. If that is the issue, change the name of the field. (most likely in props.conf).

Hope this helps,

/K

0 Karma

ChhayaV
Communicator

regex is proper i am able to use the fileds in query and i have given simple string names its not containing hyphen

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...