Is there anyway to alter the default results table formatting in the Logs section when any user enters?
- Lines per row
- What fields are selected
Secondary question related to processing rule using example contents of log below:
- "content": "2023-01-01 12:00:00,000  ERROR SourceApp Contract 123456789 is currently being processed (additional text)",
How would you construct processor definition to parse out the remaining content after 'SourceApp ' to end of contents [Contract 123456789 is currently being processed (additional text)] into a field named "message" ?
My goal is to remove unnecessary information at the head of the content field, replaced with message field, to enhance user experience viewing logs from this source.