Hi
is there a way (in Splunk Web or from the CLI) to see if a field was extracted at search time or at index time?
Thanks
Chris
I don't believe this is possible.
View solution in original post
I guess you're right