I’m feeding a firewall and a domain controller into Graylog so I have tons of different fields.
I have a usability question. In 3.1.x in the “normal” search view I was entering the search and then did actions (like quick values) with the fields displayed on the left side. For example I was entering a full-text query for “conn_open” and the results were showing me all firewall logs with connection opening for the last five minutes by default. At the same time on the left side of the window the fields were reduced to fields available in the results and I could quickly pick one.
Now with 3.2.1 whatever search I do it always displays all fields on the left side. So I have to scroll a lot and even worse I can’t remember all of the field names so it’s a bit of a guessing until I find the right field.
Is there any configuration I can do to have back the 3.1 behaviour and only see fields that are part of the current search results?