Splunk Search

Are you extracting the controller field?

aalapsharma
Engager

I do not see it in the props.conf

0 Karma
1 Solution

sdaniels
Splunk Employee
Splunk Employee

It might help to provide more information and context to your issue. Reading a couple of the docs should help you. There are several reasons that you may not be seeing a field. Your user might not have the permissions, there might not be a configuration to extract the field at search time etc... You could always add a field using the interactive field extractor (here).

http://docs.splunk.com/Documentation/Splunk/6.0/Knowledge/Addfieldsatsearchtime

There are also several places to look for configuration files:
http://docs.splunk.com/Documentation/Splunk/6.0/admin/Wheretofindtheconfigurationfiles

View solution in original post

aalapsharma
Engager

Sorry I thought the question would be directed to the creator of the app. However I used the interactive field extractor and its pretty cool.

sdaniels
Splunk Employee
Splunk Employee

It might help to provide more information and context to your issue. Reading a couple of the docs should help you. There are several reasons that you may not be seeing a field. Your user might not have the permissions, there might not be a configuration to extract the field at search time etc... You could always add a field using the interactive field extractor (here).

http://docs.splunk.com/Documentation/Splunk/6.0/Knowledge/Addfieldsatsearchtime

There are also several places to look for configuration files:
http://docs.splunk.com/Documentation/Splunk/6.0/admin/Wheretofindtheconfigurationfiles

lukejadamec
Super Champion

A little more info. We are a very distributed system with a slow bus speed.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...