Hi,
Maybe I did't understand the documentation. I did a summery index from a query built in my main index. In my main Index I have tons of field like USERID, FIRSTNAME, etc.. some are binded to lookup table.
I don't know why I lost all of them in the summary index, even the basic field. It looks like the Splunk does understand the line anymore and only shows very fews fields in the left side. There is not a lot of options in the GUI so I don't know if it is maybe something I have to do under the hood, directly in the ascii file like the transform file.
Thanks
... View more