Hello, I need help in search and extractors, the elasticsearch find more fields than they really are

If in one field of my message exist “,” for example:

misg=“XX=xxx, YY=tt, … ZZ=iii”

And the search shows for example misg, XX, YY, …, ZZ like a fields but the real field is misg.

How to remove the XX, YY, ZZ and show only misg? Or… How to show only the fields find for the extractors?

Regards

Sorry @alfa

I do not get your question.

I have fields in one of my fields and Graylog recognizes them as fields to each of these, I do not know if I am expressing myself correctly

maybe you post a screenshot?

I found that I would to change something in Mongodb for this. Thanks for your time

sharing is caring - what did you do? Maybe someone else can learn?

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.