If these are internal applications, I presume this means you also have custom props.conf and transforms.conf for the logs?
If you add new field extractions because of newer logging contents, then you will only see those newer fields in the newer data – because they won’t exist in the older data
from User warren – Stack Overflow https://stackoverflow.com/questions/68663778/find-all-newer-events-logged-by-application-after-a-certain-date-in-splunk/68671302#68671302
via IFTTT