So let's say I have this tag in /opt/splunk/etc/apps/search/local/tags.conf:
[host=x.y.uci.edu]
nac_wsg = disabled
nac_dba = enabled
So now I go into the GUI and under Splunk > Manager >> Tags I click on List by tag name. App context is Search and Owner is Any. I do not see nac_dba or nac_wsg (nor a number of other tags). I only see a few. What is up with that?
Then I go into Splunk > Manager >> Tags and click on List by field value pair. App context is Search and Owner is Any. I do see host=x.y.uci.edu but I do not see anything under Tag Name.
Now I checked that /opt/splunk/etc/system/local/tags.conf is empty, and also that the various users local/tags.conf don't have anything.
This is splunk 4.3.1.
I verified all this after a fresh restart of splunk.