To search for a tag on a specific field, Splunk requires the syntax tag:: < field > = < tagname > .
Extract: “To search for a tag associated with a field, use tag:: < field > = < tagname > .”
Thus, tag::host=prod is correct.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit