when using the following search:
source="/data/log/rla.log" eventtype="SessionStart" | convert ctime(_time) as timestr | table timestr, user, wanIP, NCIP, hostname | sendemail email@example.com sendresults=t
the columns start with wanIP, NCIP, timestr, etc.... Is there a way to force the order of the columns to what I want which is timestr, user, wanIP, etc...
This is bug SPL-31616 fixed in 4.1.4.
thanks, I will upgrade at the first oppourtunity