Splunk Search

Why splunk stop to extract new fields for some reason?

imanpoeiri
Communicator

Hi Splunkers,

I will cut the intro and talk straight to the problem:

I have 5 fields that were declared on props.conf, lets say:

[sourcetype_name]
INDEXED_EXTRACTIONS=csv
TIMESTAMP_FIELDS ="datefield"
FIELDALIAS-alias-may="field1" AS fieldA "field2" AS fieldB "field3" AS field3 "datefield" AS date_created "field5" AS fieldE

I can find field1, fieldA, field2, fieldB, datefield, field5 on the indexed fields, but not for date_created, and fieldE.

but when i move the "field3" AS field3 to the very last of the line, I can find datefield, date_created, field5, and fieldE.

I know it is not a best practice to put the same field name in the props.conf, but why splunk stop the field extraction when it hit error? I think splunk should be able to ignore the error on thus field and continue to extract the next fields.

Can I consider this as a bug?

0 Karma

woodcock
Esteemed Legend

I could go either way on it myself but tend to agree with you. You have nothing to lose by filing a bug report with support.Splunk.com.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...