Splunk Search

Are you extracting the controller field?

aalapsharma
Engager

I do not see it in the props.conf

0 Karma
1 Solution

sdaniels
Splunk Employee
Splunk Employee

It might help to provide more information and context to your issue. Reading a couple of the docs should help you. There are several reasons that you may not be seeing a field. Your user might not have the permissions, there might not be a configuration to extract the field at search time etc... You could always add a field using the interactive field extractor (here).

http://docs.splunk.com/Documentation/Splunk/6.0/Knowledge/Addfieldsatsearchtime

There are also several places to look for configuration files:
http://docs.splunk.com/Documentation/Splunk/6.0/admin/Wheretofindtheconfigurationfiles

View solution in original post

aalapsharma
Engager

Sorry I thought the question would be directed to the creator of the app. However I used the interactive field extractor and its pretty cool.

sdaniels
Splunk Employee
Splunk Employee

It might help to provide more information and context to your issue. Reading a couple of the docs should help you. There are several reasons that you may not be seeing a field. Your user might not have the permissions, there might not be a configuration to extract the field at search time etc... You could always add a field using the interactive field extractor (here).

http://docs.splunk.com/Documentation/Splunk/6.0/Knowledge/Addfieldsatsearchtime

There are also several places to look for configuration files:
http://docs.splunk.com/Documentation/Splunk/6.0/admin/Wheretofindtheconfigurationfiles

lukejadamec
Super Champion

A little more info. We are a very distributed system with a slow bus speed.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...