Index=A sourcetype=B and I can see under fields category filed "C" with count of 10k+ values ..
But if I search with Index=A sourcetype=B category=C , It is showing No results found tried in all the search modes didn't worked. source tcp:9997 . Can some one please suggest what can be the issue.
Great! So, if you set this field as INDEXED on your search head, you will not need to use :: syntax. You can use below sample, than you will be able to search field=*
fields.conf [field] INDEXED=true
Is it possible that your category field is being sent to Splunk as a _meta? Please try searching like below;
I assume your field is C;
index=A sourcetype=B C::*
If I got it right, on your first search you see category values under C field? If so, you should use below search to filter categories;
index=A sourcetype=B C=*
If I missed something, please give a sample logs, result in screen capture.
If this reply helps you an upvote is appreciated.