Hello,
I have events with different lengths for _raw field within the same source. I would need to limit/minimize the length of _raw field in some case. How I would limit the maximum length of string that would display for _raw field using queries from search head. Any help will be greatly appreciated, Thank you so much
Are you looking for something like this?
... | eval _raw = substr(_raw, 1, min(len(_raw),80))
Are you looking for something like this?
... | eval _raw = substr(_raw, 1, min(len(_raw),80))