Splunk Search

TAGS not showing in Field Discovery panel when a wildcard is used

Rob_Jordan
Explorer

I should mention that both the standard and wildcard tags both return search results, but the wildcard tag does not show up in the field discovery panel.
All of the following searches work:

tag=QA
tag=*
tag::host=QA
tag::host=*

Field Discovery Working:
Here's an example of a tag I've created which shows as a field in the format of tag::host.

Tag Name: QA
Field value pair: host=abcd.com

Field Discovery Not working:
When I add the wildcard to cover variations of the hostname i.e. short and long, the search works and returns results, but I do not see the field tag::host in the field discovery panel.

Tag Name: QA
Field value pair: host=abcd*

Thanks,

Rob

0 Karma

bkahlerventer
Explorer

Wildcards are allowed from 6.x onwards as far as I know, but the tags still does not show in the field discovery panel.

I suspect that the field discovery panel receive its collection of fields before the tags are added to the event. The best is to log a Case with Splunk if you have a Support Contract.

0 Karma

mrodriguez360
New Member
0 Karma
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...