When I apply ingest actions and I specify host field and put in the IP address, it works fine but when I try to use _raw and for instance; filter on
Teardown ICMP connection
, it shows the affected events but when I check hours or days later, it still ingests the messages filtered by using the _raw as the field.