The environment is Deployment Server and Client configuration.
We can see several hosts. but when host field is selected,
We can see hostname garbage(space or blank ) on the Search line.
ex) index=ABC host="ABCDEF " <-- one space
but, We can see if this like
index=ABC host="ABCDEF*" <-- if put *
so, We can not have any other search from the search line.
what is solution ?
Maybe you should try regex:
index=ABC host=ABCDEF\s
or
index=ABC host=ABCDEF?
See your Splunk Quick Reference Guide for more on RegEx.
http://docs.splunk.com/images/1/17/4.2.x_search_language_refcard.pdf