Display log information

The default display "_source" has a lot of uninteresting data. So I went to advanced settings and modified the default columns to be "winlog.event_id, event.action, winlog.event_data.SubjectUserName, winlog.event_data.SubjectDomainName, winlog.event_data.ObjectType, winlog.computer_name, winlog.event_data.IpAddress, winlog.event_data.IpPort" However, the time column is so wide it shoves my other columns off the page. I am not able to resize the columns. In addition, some entries are blank because it is a different log type.
Is there a way to add multiple column headers in one column so that I can display interesting data for both a logon event and a sysmon event or any event?
Thanks,
Gary

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.