Question on Best Practice and original message

Quick question on best practices related to original, raw syslog messages (pre-processing).
After grokking the data into fields, is it best practice to keep the original “message” field or would it make sense to drop that field in the name of storage capacity or other reasons?

Opinions welcome.

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.