I believe this is a bug in splunk I noticed that I'm getting the following error message in my console when expanding events that are not showing the fields. This error doesn't happen when expanding the other events. JS Console error when expanding the event Those are the JSON I'm using for this test 1) {
"Show all actions": true
} 2) {
"Show All actions": true
} My console shows the error when expanding the event 1, but it doesn't when expanding the event 2. The only different between the events is the letter "a" in the word all (which is uppercase in the event 2). I'm using Splunk Enterprise 8.0.4 To reproduce this problem I created a HEC, and sent the JSON bellow to the HEC {
"time": 1592251280.000,
"host": "localhost",
"source": "test.json",
"index": "all_problem",
"sourcetype": "_json",
"event": {
"Show all actions": true
}
}
{
"time": 1592251275.000,
"host": "localhost",
"source": "test.json",
"index": "all_problem",
"sourcetype": "_json",
"event": {
"Show All actions": true
}
} Search result:
... View more