This is probably pretty straightforward but on my search head the following will not return any results:
index=train sourcetype=transcript slotID=1234
whereas the following will:
index=train sourcetype=transcript | search slotID=1234
slotID is a unique field extracted via props/transforms. Permissions are defined as read:everyone, write:admin What am I doing wrong?
Note that for other searches, I can query a unique field and it results will be returned: index=train sourcetype=transcript status=running (here "status" is extracted via the same props/transforms mechanism)
This typically happens for two reasons.
This typically happens for two reasons.