|
I have a I thought that that this only happened for extracted fields where the value is not in the actual event |
|
By default, Splunk will expand If this is because store is an extracted field or lookup-based field, tell Splunk to not search for the text in the event by editing fields.conf:
|
