synesis_lite_syslog icon indicating copy to clipboard operation
synesis_lite_syslog copied to clipboard

Removing event.message but log.message cannot be searched

Open luminous706 opened this issue 3 years ago • 0 comments

Hello,

Since event.message and log.message are pretty much a duplicate of the logs, I decided to drop event.message since we have a cleaner log.message - this allows to save space as some logs are quite long.

But when I search using "query strings" in Kibana, it doesn't search log.message at all. It does search event.message when it's there as well as other fields such as log.process.

I don't know why Kibana refuses to search log.message when using "query strings" (just typing a word or sentence with double-quotes in the KQL box), can you help?

Thanks!

luminous706 avatar Oct 14 '20 21:10 luminous706