I like to find out how a particular field is extracted from a given sourcetype. Can I find this via splunk front end using metadata or similar command?
If I understand you correctly, like this (be sure to swap out PutYourSourcetypeHere and PutYourFieldNameHere with your strings):
| rest/services/configs/conf-props sourcetype="PutYourSourcetypeHere" | eval fields_with_string="," | foreach * [eval fields_with_string=if((like($<<FIELD>>$, "%PutYourFieldNameHere%")), fields_with_string . $<<FIELD>>$ . ",", fields_with_string)] | where fields_with_string!=","
Give a complete example of what you have as data and what you expect to get as a result of your search. I have no idea what you are asking.