Splunk Search

Why splunk stop to extract new fields for some reason?

imanpoeiri
Communicator

Hi Splunkers,

I will cut the intro and talk straight to the problem:

I have 5 fields that were declared on props.conf, lets say:

[sourcetype_name]
INDEXED_EXTRACTIONS=csv
TIMESTAMP_FIELDS ="datefield"
FIELDALIAS-alias-may="field1" AS fieldA "field2" AS fieldB "field3" AS field3 "datefield" AS date_created "field5" AS fieldE

I can find field1, fieldA, field2, fieldB, datefield, field5 on the indexed fields, but not for date_created, and fieldE.

but when i move the "field3" AS field3 to the very last of the line, I can find datefield, date_created, field5, and fieldE.

I know it is not a best practice to put the same field name in the props.conf, but why splunk stop the field extraction when it hit error? I think splunk should be able to ignore the error on thus field and continue to extract the next fields.

Can I consider this as a bug?

0 Karma

woodcock
Esteemed Legend

I could go either way on it myself but tend to agree with you. You have nothing to lose by filing a bug report with support.Splunk.com.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...