Splunk Search

Problem with extracted field

ChhayaV
Communicator

Hi,

I am not able to see extracted fields in "Interesting field list",however fields are visible in Manager.
What can be the problem ?

Thanks and Regards

Tags (1)
0 Karma

dmlee
Communicator

below are my suggestion :
1st, check the permission and app of the field you defined , you must be in the same app as the field belongs to ( if you share to "App" but not to "global" )
2nd, click the "edit" icon on the upper right corner of "Interesting field list" , you can see all fields list
3rd, if you cannot find specific field that you defined before , may be the reason is there is no matched rule in your search result

0 Karma

ChhayaV
Communicator

hi, 1st I have kept permisisons for all the extracted fields as global
2nd Its not showing extractes fields
3rd Its matching because i can use those fields in my query its working. i am not able to see it in "Interesting field list"

0 Karma

kristian_kolb
Ultra Champion

My guess is that either;

a) the regex for extracting the field is not matching any event in your search results. This is then the expected behaviour. The definition will always be visible in manager, but if no event matches the regex, then the field name will not show in the search app, as the field is not present in the events. Or perhaps your extraction regex is wrong and needs to be edited.

b) your field name contains a hyphen (dash/minus/-). That used to be a problem when you created fields, but maybe that has been fixed by now. If you created your field extraction through IFX, you didn't get an error message. Normally fields names shall only contain letters, numbers and underscores, and must start with a letter. If that is the issue, change the name of the field. (most likely in props.conf).

Hope this helps,

/K

0 Karma

ChhayaV
Communicator

regex is proper i am able to use the fileds in query and i have given simple string names its not containing hyphen

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...