Summary:
When using the table command, values are dropped if { is the first character.
Hi
this sounds like a bug. Please report it to splunk support.
r. Ismo
Hi @jaxxsplunk,
only for your information, if you rename a field "| rename ID as "Rcrds Prcssd To Date"" the following " | sort -ID" doesn't run because the ID field isn't yet present!
Anyway, probably there's an error in "EVENT" field extraction.
We could help you, if you share a sample of your logs and the regex that you're using to extract the "EVENT" field to understand why sometimes your field extraction doesn't run.
The difference between table and fields is that table is a steaming command, instead fields is a non streming field, you can find a description of the command types at https://docs.splunk.com/Documentation/Splunk/8.2.4/Search/Typesofcommands
Ciao.
Giuseppe