I worked with splunk support and they were able to provide some work arounds for this issue. First off they pointed me to another answer here: http://answers.splunk.com/questions/7093.
Here is the answer they provided:
instead of running your searches as: host= ORD=IV you can run them as host= ORD=*IV - this will work
instead of running your search as host= ORD=IV you can run them as host= | search ORD=IV - this will work
instead of doing the above, you can keep running your searches exactly the way you are running them, however you need to add the following configuration within a fields.conf (say under /etc/apps/search/local/fields.conf) or wherever you are collecting your configs. This third workaround requires a Splunk Restart. Here is the exact stanza you need (cat fields.conf) :
[ORD]
INDEXED_VALUE=false
I have confirmed that the first two do work correctly and provide the expected results. We have not had a chance to restart or splunk app as it is under near constant use.
... View more