Splunk Search

Why is "host=OptionalProperties" appearing as a field=value pair when we don't have a host by this name?

Path Finder

Why is this value appearing as a field value? It only shows a count of 3. There is no host by this name and no results appear if host=OptionalProperties is added to the search.

0 Karma

Explorer

one cause is probably because you have the data in your log with an automated extraction at read (default behavior) with host=OptionalProperties
try a search like
index=msad "host=OptionalProperties"
to confirm.

0 Karma