1 comment

  • Avatar
    Kevin Keech

    The "message" field will need to be referenced as "_raw" which is the underlying metadata name. So the following should work to get you the messages larger than 100 bytes. 

    | where length(_raw) > 100

    Sumo Logic also provides a "_size" metadata for each message, which contains the byte size of a message. So you can also use the following to check for message size. 

    | where _size > 100

    More info on the available metadata for messages can be found in the following help.

    Comment actions Permalink

Please sign in to leave a comment.