Wow. For all my queries, I had been using the following fields command under the assumption it did drop _raw. | fields _time, xxx, yyy, zzz, .... Then one day I started a large mvex...
See more...
Wow. For all my queries, I had been using the following fields command under the assumption it did drop _raw. | fields _time, xxx, yyy, zzz, .... Then one day I started a large mvexpand and ran into memory limit. My thought upon seeing this was 'Huh? Well, worth a try I guess.' | fields _time, xxx, yyy, zzz, ....
| fields - _raw Boom, mvexpand completes successfully. The heck? It actually cut the search time in half too.