Splunk Search

Problem with extracted field

ChhayaV
Communicator

Hi,

I am not able to see extracted fields in "Interesting field list",however fields are visible in Manager.
What can be the problem ?

Thanks and Regards

Tags (1)
0 Karma

dmlee
Communicator

below are my suggestion :
1st, check the permission and app of the field you defined , you must be in the same app as the field belongs to ( if you share to "App" but not to "global" )
2nd, click the "edit" icon on the upper right corner of "Interesting field list" , you can see all fields list
3rd, if you cannot find specific field that you defined before , may be the reason is there is no matched rule in your search result

0 Karma

ChhayaV
Communicator

hi, 1st I have kept permisisons for all the extracted fields as global
2nd Its not showing extractes fields
3rd Its matching because i can use those fields in my query its working. i am not able to see it in "Interesting field list"

0 Karma

kristian_kolb
Ultra Champion

My guess is that either;

a) the regex for extracting the field is not matching any event in your search results. This is then the expected behaviour. The definition will always be visible in manager, but if no event matches the regex, then the field name will not show in the search app, as the field is not present in the events. Or perhaps your extraction regex is wrong and needs to be edited.

b) your field name contains a hyphen (dash/minus/-). That used to be a problem when you created fields, but maybe that has been fixed by now. If you created your field extraction through IFX, you didn't get an error message. Normally fields names shall only contain letters, numbers and underscores, and must start with a letter. If that is the issue, change the name of the field. (most likely in props.conf).

Hope this helps,

/K

0 Karma

ChhayaV
Communicator

regex is proper i am able to use the fileds in query and i have given simple string names its not containing hyphen

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...