Hi, How many fields do you have in your event? If it is more than 100 fields then you need to increase below settings in limits.conf on SH. [kv]
limit = <integer>
* The maximum number of fields that an automatic key-value field extraction
(auto kv) can generate at search time.
* The summary fields 'host', 'index', 'source', 'sourcetype', 'eventtype',
'linecount', 'splunk_server', and 'splunk_server_group' do not count against
this limit and will always be returned.
* Increase this setting if, for example, you have data with a large
number of columns and want to ensure that searches display all fields extracted
from an automatic key-value field (auto kv) configuration.
* Set this value to 0 if you do not want to limit the number of fields
that can be extracted at index time and search time.
* Default: 100
... View more