Splunk Search

[tpl10082inf63] Field 'total' does not exist in data

sachinbansal
New Member

Hi,
I am using below query. I am getting data but in chart i am getting warning '[tpl10082inf63] Field 'total' does not exist in data'

index=systest sourcetype=vmreport
| rex max_match=1000 "\Name\s\s\s\s\s\s\s:\s\s(?.)<\/TD>\Guest"
| rex max_match=1000 "\Guest\s\s\s\s\s\s:\s\s(?.
)<\/TD>\State"
| rex max_match=1000 "\State\s\s\s\s\s\s:\s\s(?.*)<\/TD>\

Tags (1)
0 Karma

yannK
Splunk Employee
Splunk Employee

We do not see the query referring to a field "total".
So maybe is it something coming from a different place ( automatic field extractions, automatic lookups, role search filter ...) ?

kamlesh_vaghela
SplunkTrust
SplunkTrust

@sachinbansal

Can you please share sample event?

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...