fields
Include or exclude fields from the event stream.
Syntax
| fields [+|-] <field> [, <field> ...]
+(default): Include only these fields-: Remove these fields
Examples
-- Include specific fields
| fields source, level, message
-- Remove fields
| fields - _raw, _id
-- Keep only what you need
level=error | fields + _time, source, message
Notes
fieldswithout a prefix defaults to include mode (same asfields +).fields +is equivalent totable.- The optimizer uses field lists for column pruning, reducing I/O.