I'm getting different search results for the metadata I added to my log events. What did I misconfigure?
Added to inputs.conf on forwarder: _meta = datacenter::aws
Added to fields.conf on forwarder: [datacenter] INDEXED=true
Returns very few results:
datacenter=aws
Returns all results:
datacenter::aws
In this case, you need to have the fields.conf on your search head (where you’re searching.)
Additionally, there is an inherent difference between a search for field=a and field::a
The later of these is relevant for indexed fields. Search through your job inspector to see how the jobs are parsed differently.