Splunk Search

[tpl10082inf63] Field 'total' does not exist in data

sachinbansal
New Member

Hi,
I am using below query. I am getting data but in chart i am getting warning '[tpl10082inf63] Field 'total' does not exist in data'

index=systest sourcetype=vmreport
| rex max_match=1000 "\Name\s\s\s\s\s\s\s:\s\s(?.)<\/TD>\Guest"
| rex max_match=1000 "\Guest\s\s\s\s\s\s:\s\s(?.
)<\/TD>\State"
| rex max_match=1000 "\State\s\s\s\s\s\s:\s\s(?.*)<\/TD>\

Tags (1)
0 Karma

yannK
Splunk Employee
Splunk Employee

We do not see the query referring to a field "total".
So maybe is it something coming from a different place ( automatic field extractions, automatic lookups, role search filter ...) ?

kamlesh_vaghela
SplunkTrust
SplunkTrust

@sachinbansal

Can you please share sample event?

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...