Splunk Search

Splunk UI misbehavior for the parsing of the logs

DionisMjeku
Engager

I've noticed in the last days, after the deployment process is done we are having some problems when making searches on most of the indexes.

For example, when searching within index=*db_oracle, even essential fields like source, index, and sourcetype (which i didnt alter) are missing on search for about 1-2 hours or more post deployment, now after some days this is repeating that each search does not return at least 3-4 fields which appear if i search again.

This delay is obstructing us to validate changes and proceed with field normalizations during this period, as the searches arent reflecting accurate information on extracted fields.

Also in for License Manager I noticed a Warning in Disk Space.

Labels (1)
Tags (2)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

Also in for License Manager I noticed a Warning in Disk Space.

Shouldn't you address the disk space warning first?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @DionisMjeku ,

it isn't a behaviour that I didn't see before, open a case to Splunk Support.

Only for my information: you always don't see indexed fields (as source, sourcetype or host) or in the first time you see them and then, after some time, you don't see them?

Ciao.

Giuseppe

DionisMjeku
Engager

Hi its not letting me create a case :(. Yes its an issue with searching because even if i go to all fields they sometimes appear sometimes not which never happened before. Also it only happened on logs from oracle metadata in both ESH and MC search.

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...