Splunk Search

[tpl10082inf63] Field 'total' does not exist in data

sachinbansal
New Member

Hi,
I am using below query. I am getting data but in chart i am getting warning '[tpl10082inf63] Field 'total' does not exist in data'

index=systest sourcetype=vmreport
| rex max_match=1000 "\Name\s\s\s\s\s\s\s:\s\s(?.)<\/TD>\Guest"
| rex max_match=1000 "\Guest\s\s\s\s\s\s:\s\s(?.
)<\/TD>\State"
| rex max_match=1000 "\State\s\s\s\s\s\s:\s\s(?.*)<\/TD>\

Tags (1)
0 Karma

yannK
Splunk Employee
Splunk Employee

We do not see the query referring to a field "total".
So maybe is it something coming from a different place ( automatic field extractions, automatic lookups, role search filter ...) ?

kamlesh_vaghela
SplunkTrust
SplunkTrust

@sachinbansal

Can you please share sample event?

0 Karma
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...