Thanks for your guidance, I would like to include additional fields in the fields tab in Search result. I have took a look at the extractors and configured accordingly. For instance, this is the message to parse:
2019-03-12 10:15:51 [https-jsse-nio-8020-exec-10] INFO : ASCPA7C500611418 ab.bc.cde.efg.common.rest.endpoints.component.filter End
However, I want just to add “class” field in the list. How can I get rid of the other fields? I already attempted to keep just JAVACLASS, but I am not getting the appropriate value for the class.
Thanks a lot Jan, this option worked when including grok statements. However, I am looking at how to drop the filebeat fields from the search page. I did configuring a pipeline and relating it to a rule with the following Rule source: