Querying Events' Fields

Querying data in Humio is performed by searching either the raw data of events or by selecting data from specific fields extracted from the event when the data is parsed.

There are different kinds of fields coming from the events:

  • Tag fields # define how events are physically stored and indexed.

  • Metadata fields @ are the metadata attached to each event on ingestion. All events will have an @id, @timestamp, @timezone, and @rawstring.

  • User fields is any field that is not a tag or metadata field.

Event fields can be viewed and managed from the Humio User Interface, see Accessing Data in Repositories and Views for more information.

Learn how to query these fields in Humio and discover what you can achieve with query writings at Managing Queries and Frequently Used Query Operations.