I see a similar issue reported here, but thread was locked so I couldn’t pile on.
New install inside a docker container with single source (dns server) pushing logs in so far. I created multiple extractors for queries and responses, then realized as I was creating a third that I could merge them all into a single extractor. So, I deleted the two existing and reworked the third to cover all message types.
But incoming messages are still being parsed by the now deleted extractors based on the field names being created. And some of the messages aren’t being parsed at all, yet when I put that specific message into the tester in the extractor edit page it parses correctly. The new extractor is firing according to the stats in its Details page.
It feels like some process needs to be restarted to flush the old out and load the new in. Is there a way to force that? Or is there any other reason why the old extractors would still be parsing messages hours after they’ve been deleted?