One source category has a combination of several different log files from the same device that should be parsed with FERs for easier searching. The first FER has a broad scope that extracts three fields common to all log file sources. The second FER is narrowly scoped for only one log file source in the category by adding more search words to the scope in addition to the _sourceCategory, as per the documentation. However, the fields from the narrowly scoped FER appear as "Hidden Fields" when searching the first, more broadly-defined scope. Of course, these fields have "Null Value" all over as the fields only apply to the second narrow scope. These fields are confusing, even if hidden.
Why do these Hidden Fields appear when searching the broad scope? Am I doing something wrong?
Please sign in to leave a comment.