great answer by lowell in that first link, and definitely worth reading the indexed extractions docs through.
The search syntax field::value is a great quick check, but playing with walklex is definitely worth the time, and gets my vote, as it is the ultimate source of truth and will be a great trick to add to your Splunk Ninja arsenal!
More on it, and other cool debug tools here:
https://docs.splunk.com/Documentation/Splunk/7.2.3/Troubleshooting/CommandlinetoolsforusewithSupport#walklex
also, for extra homework ;), check out @martin_mueller and his amazing talk on fields and tokens:
https://conf.splunk.com/files/2017/recordings/fields-indexed-tokens-and-you.mp4
https://conf.splunk.com/files/2017/slides/fields-indexed-tokens-and-you.pdf
... View more