Splunk Search

TAGS not showing in Field Discovery panel when a wildcard is used

Rob_Jordan
Explorer

I should mention that both the standard and wildcard tags both return search results, but the wildcard tag does not show up in the field discovery panel.
All of the following searches work:

tag=QA
tag=*
tag::host=QA
tag::host=*

Field Discovery Working:
Here's an example of a tag I've created which shows as a field in the format of tag::host.

Tag Name: QA
Field value pair: host=abcd.com

Field Discovery Not working:
When I add the wildcard to cover variations of the hostname i.e. short and long, the search works and returns results, but I do not see the field tag::host in the field discovery panel.

Tag Name: QA
Field value pair: host=abcd*

Thanks,

Rob

0 Karma

bkahlerventer
Explorer

Wildcards are allowed from 6.x onwards as far as I know, but the tags still does not show in the field discovery panel.

I suspect that the field discovery panel receive its collection of fields before the tags are added to the event. The best is to log a Case with Splunk if you have a Support Contract.

0 Karma

mrodriguez360
New Member
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...