Eg :
index = userinformation
_raw doesnt have any field or value related to field "ue".
But "ue" is being shown in Interesting Fields.
ue = abc@splunk.com
ue = xyz@splunk.com
So my questioning is what is generating this field to exist in the index?
Look for INGEST_EVAL
statements in transforms.conf.
forgive my ignorance, but I don't understand the answer.
Do I look on my indexers (all 3 in my case) for this?
What am I looking for?