If I do a search like this:
index=* sourcetype=* host=* 1.1.1.1
And I get millions of responses from dozens of sourcetypes, how can I return the name of the field(s) where 1.1.1.1 occurs?
I don't have time to chunk through thousands of possible fields looking for my data. The best suggestion I've heard to date is a rex that looks backwards and returns pre-equal-sign data. I have a hard time believing there isn't an easier / more elegant solution. Can anyone help?
This example will show you all of the fields which contain the value shelper
index=_internal shelper | fieldsummary | search values=shelper | table field
This example will show you all of the fields which contain the value shelper
index=_internal shelper | fieldsummary | search values=shelper | table field
If I could vote this up a hundred times, I would. I use this all the time.