When the Data Volume Index is enabled the index starts to populate. This data does not backfill. A set of messages within the index is created every five minutes.
- When I use Save to Index, metadata fields from the Collector (for example, _collector) will be dropped. Does that mean the data in the index will not have any associated metadata?
- Is there a way to block or allow specific logs from being ingested?
- Collector is in Deactivated state and fails to restart
- Using line breaks as an anchor within parse