Select & Filter Fields

Select single fields to search and filter on those fields.

  1. Click on a field in the Fields panel#severity in the example: a resizable flyout opens with the list of values found and the number of occurrences for each.

    Select Fields

    Figure 51. Select


  2. Click the icon next to a field name to get several filtering options.

    Filtering Options

    Figure 52. Filtering Options


  3. Select one of the options: for example, AggregateGroup by value will group events by the value of that field, TimechartUse field as series will run the timeChart() function in the Query editor to show events that have that field grouped into series and plotted in a timechart.

More filter options and interactions with fields are available, such as exclude () or include (⊜) in the search all events that have the selected field.

When the menu is opened for Field Interactions with live queries, the Fields panel flyout will display a fixed list of top values. The top values are kept from the point in time when the menu was opened. See Field Interactions for more information.