Does anyone know any tricks to let you have an inline comment in search dialog of Discover? For instance for a "Firewall Drops" saved search I want to have something like this:
panw.panos.sub_type : ("drop" or "deny") /* and source.ip : "0.0.0.0" */
So that they can then set the source IP easily to narrow the search. We are trying to roll Kibana out to a wider audience in IT.
I added the instruction to the comments for the saved search, but when loading a saved search the user never sees that note?
The only problem I am having is that when it is in ESQL mode I had to rebuild the field selection list, which is fine... but... it will not let me have the @timestamp as the first field. I can have it in any other position but when it moves to the first column it gets removed from the selected fields list. Not sure if that has something to do with the feature being in preview for 8.12.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.