Hi, I got one weird problem that when I run query in splunk, there're events found, but the Event log field is always blank. However, the problem will be fixed by below steps: in the Splunk search result, go to All Fields at left rail change Coverage: 1% more to All fields click Deselect All click Select All Within Filter Then the problem is fixed, I can see the Event logs. Even I change from All fields back to Coverage: 1% more, I can still see Events logs. But after I close the browser tab and go to Splunk and search again, the problem still exists. So the problem is, why Coverage: 1% more will have problem to me for the first time query? Anyone has idea about this? Thanks.
... View more