Splunk Search

Splunk UI misbehavior for the parsing of the logs

DionisMjeku
Engager

I've noticed in the last days, after the deployment process is done we are having some problems when making searches on most of the indexes.

For example, when searching within index=*db_oracle, even essential fields like source, index, and sourcetype (which i didnt alter) are missing on search for about 1-2 hours or more post deployment, now after some days this is repeating that each search does not return at least 3-4 fields which appear if i search again.

This delay is obstructing us to validate changes and proceed with field normalizations during this period, as the searches arent reflecting accurate information on extracted fields.

Also in for License Manager I noticed a Warning in Disk Space.

Labels (1)
Tags (2)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

Also in for License Manager I noticed a Warning in Disk Space.

Shouldn't you address the disk space warning first?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @DionisMjeku ,

it isn't a behaviour that I didn't see before, open a case to Splunk Support.

Only for my information: you always don't see indexed fields (as source, sourcetype or host) or in the first time you see them and then, after some time, you don't see them?

Ciao.

Giuseppe

DionisMjeku
Engager

Hi its not letting me create a case :(. Yes its an issue with searching because even if i go to all fields they sometimes appear sometimes not which never happened before. Also it only happened on logs from oracle metadata in both ESH and MC search.

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...