when using the following search:
source="/data/log/rla.log" eventtype="SessionStart" | convert ctime(_time) as timestr | table timestr, user, wanIP, NCIP, hostname | sendemail to=tim.freeman@blah.com sendresults=t
the columns start with wanIP, NCIP, timestr, etc.... Is there a way to force the order of the columns to what I want which is timestr, user, wanIP, etc...
 
		
		
		
		
		
	
			
		
		
			
					
		This is bug SPL-31616 fixed in 4.1.4.
thanks, I will upgrade at the first oppourtunity
