I am trying to upload logs and whenever I do the logs come out scattered. Do I have to give every colum a title e.g In the column where there are src_ip's do I have to indicate that as the header of that column? Because in the raw logs there isn't anything of such just values. Anytime I try doing a query for example index=** sourcetype=*** | top limit=10 user src_ip It doesn't give me any result. The only time I get a result is just with the index=** sourcetype=*** In the second photo attached, the INTERESTING FIELD has the values instead of the name. How do i resolve this, pleasssse!! Been stuck here.
... View more