Hello,
Basically, we want to get the rid of the system fields except _time , but leave the ones it picks up from our event, for example, get rid of date_mday, date_month etc. And keep the custom ones. is there any easy way to do this?
Create a macro
called nofields
or something that consists of fields - date_*
or whatever you like and then add it to all of your searches like this:
... | `nofields`
what do you mean get rid?