it returns the correct results. So the tag can be searched, but there is no tag field in the fields list. If instead you run this search:
tag=S100 | stats count by tag
it doesn't return any result. I could reproduce the issue both on Splunk 6.1.1 and 6.0. After replacing the Russian text in Message="" in the eventtype definition in eventtypes.conf with any English text, it started to work as expected.
Could you please tell me if this is a bug and how this can be workarounded?