I've noticed in the last days, after the deployment process is done we are having some problems when making searches on most of the indexes.
For example, when searching within index=*db_oracle, even essential fields like source, index, and sourcetype (which i didnt alter) are missing on search for about 1-2 hours or more post deployment, now after some days this is repeating that each search does not return at least 3-4 fields which appear if i search again.
This delay is obstructing us to validate changes and proceed with field normalizations during this period, as the searches arent reflecting accurate information on extracted fields.
Also in for License Manager I noticed a Warning in Disk Space.
Also in for License Manager I noticed a Warning in Disk Space.
Shouldn't you address the disk space warning first?
Hi @DionisMjeku ,
it isn't a behaviour that I didn't see before, open a case to Splunk Support.
Only for my information: you always don't see indexed fields (as source, sourcetype or host) or in the first time you see them and then, after some time, you don't see them?
Ciao.
Giuseppe
Hi its not letting me create a case :(. Yes its an issue with searching because even if i go to all fields they sometimes appear sometimes not which never happened before. Also it only happened on logs from oracle metadata in both ESH and MC search.