Just curious have you run your base query to show raw events and time in Verbose mode ? If these field names are not being displayed as Interesting fields automatically, then it implies you have either set the KV_MODE=none or changed from auto to something else in your props.conf file.
Following are various settings (refer to Splunk docs: https://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf#Field_extraction_configuration)
KV_MODE = [none|auto|auto_escaped|multi|json|xml]
... View more