Splunk Search

Splunk UI misbehavior for the parsing of the logs

DionisMjeku
Engager

I've noticed in the last days, after the deployment process is done we are having some problems when making searches on most of the indexes.

For example, when searching within index=*db_oracle, even essential fields like source, index, and sourcetype (which i didnt alter) are missing on search for about 1-2 hours or more post deployment, now after some days this is repeating that each search does not return at least 3-4 fields which appear if i search again.

This delay is obstructing us to validate changes and proceed with field normalizations during this period, as the searches arent reflecting accurate information on extracted fields.

Also in for License Manager I noticed a Warning in Disk Space.

Labels (1)
Tags (2)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

Also in for License Manager I noticed a Warning in Disk Space.

Shouldn't you address the disk space warning first?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @DionisMjeku ,

it isn't a behaviour that I didn't see before, open a case to Splunk Support.

Only for my information: you always don't see indexed fields (as source, sourcetype or host) or in the first time you see them and then, after some time, you don't see them?

Ciao.

Giuseppe

DionisMjeku
Engager

Hi its not letting me create a case :(. Yes its an issue with searching because even if i go to all fields they sometimes appear sometimes not which never happened before. Also it only happened on logs from oracle metadata in both ESH and MC search.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...