Thank you @richgalloway and @gcusello for the response... but those unfortunately weren't the answers I was looking for. Now I realise I may have not explained it the best I could; I apologise for that. The field that has been SEDCMD appears as an available field even if I search for data that does not have it in the logs. Say, it's been easily over 10 hours since the restart. Searching, right now, for the data of the last 15 minutes still shows that field, showing that it's in 100% of the logs of that search. That's what I don't understand/know how to fix. Thanks!
... View more