Quick question on best practices related to original, raw syslog messages (pre-processing).
After grokking the data into fields, is it best practice to keep the original “message” field or would it make sense to drop that field in the name of storage capacity or other reasons?
Opinions welcome.