Hello. I used the Splunk field extractor to get a field from sourcetype=sourcetype_a
For some reason, when I search sourcetype=sourcetype_b, the field I extracted for sourcetype_a is showing up. The data in that field is nothing relevant as the logs are entirely different. Why is this happening, and how can I prevent it?
Checking back now, you would be correct.. it's interesting though because in the event it is actually
key\=value which I didn't know Splunk would pick that out. Thank you!