Splunk Search

Why is "host=OptionalProperties" appearing as a field=value pair when we don't have a host by this name?

chrisduimstra
Path Finder

Why is this value appearing as a field value? It only shows a count of 3. There is no host by this name and no results appear if host=OptionalProperties is added to the search.

0 Karma

einkebil
Explorer

one cause is probably because you have the data in your log with an automated extraction at read (default behavior) with host=OptionalProperties
try a search like
index=msad "host=OptionalProperties"
to confirm.

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...