I've created some field extractions from sourcetypes such as syslog and access_common on my search head. These are all inline fields and most are regex based. When I perform a general search such as sourcetype=syslog I see all of my fields under "Interesting Fields" fine I even moved them up to 'Selected Fields" that works fine.
When I add to my search such as sourcetype=syslog internal_src_ip=10.89.X.X OR internal_src_ip=10.89.Y.Y my field extractions DO NOT show up. And I can't specify them in the command line I checked all configs such as permissions and nothing seems to be hindering that.
I have the same extractions in Splunk 6.5 and my field extractions do show up when I perform advanced searches and my field extractions do show up in the "Interesting Fields" and "Selected Fields".
So is this quirk? I have been in google and splunk answers recently so this is kinda tricky to search.
Any insight on this is greatly appreciated.