Splunk Search

Splunk UI misbehavior for the parsing of the logs

DionisMjeku
Engager

I've noticed in the last days, after the deployment process is done we are having some problems when making searches on most of the indexes.

For example, when searching within index=*db_oracle, even essential fields like source, index, and sourcetype (which i didnt alter) are missing on search for about 1-2 hours or more post deployment, now after some days this is repeating that each search does not return at least 3-4 fields which appear if i search again.

This delay is obstructing us to validate changes and proceed with field normalizations during this period, as the searches arent reflecting accurate information on extracted fields.

Also in for License Manager I noticed a Warning in Disk Space.

Labels (1)
Tags (2)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

Also in for License Manager I noticed a Warning in Disk Space.

Shouldn't you address the disk space warning first?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @DionisMjeku ,

it isn't a behaviour that I didn't see before, open a case to Splunk Support.

Only for my information: you always don't see indexed fields (as source, sourcetype or host) or in the first time you see them and then, after some time, you don't see them?

Ciao.

Giuseppe

DionisMjeku
Engager

Hi its not letting me create a case :(. Yes its an issue with searching because even if i go to all fields they sometimes appear sometimes not which never happened before. Also it only happened on logs from oracle metadata in both ESH and MC search.

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...