/
Filter on raw

Filter on raw

When your table contains a rawMessage, rawSource, or raw field, the Filter on raw search box appears embedded at the top right-hand corner of the search window by default. This useful free-text search bar carries out a search of keywords entered on raw event information.

In all data tables, the entire event is logged in a Raw field displaying event data as a string. This string will be logged as various names depending on the table: rawMessage, rawSource, or raw, however, the functionality is the same.

Use the Filter on raw field to search for keywords throughout the entire raw data field, instead of filtering by specific field.

Raw data as a table field

Although raw data is not visible by default, you can show unrevealed fields in both List and Table views using the select operation to visualise raw data as a field in the table.

When searching for results, Devo will execute various searches internally until finding a result. The order of execution is as follows:

  1. where weaktoktains (rawMessage, "<value>")"

  2. where weaktoktains (rawSource, "<value>")"

  3. where weaktoktains (raw, "<value>")"

The first clause detected will be added to the query.

See here for more information on LINQ syntax.

Supported operations

The filter on raw search functionality also supports the following LINQ operations:

  • And

  • Or

  • The wildcard “*”

  • Exact expression delimited by ““

You can also filter raw data using the Filter operation, or using the corresponding LINQ expressions.

Related content

Applied query operations
Applied query operations
Read with this
Data table
Data table
More like this
Use lookups: add lookup values to your query
Use lookups: add lookup values to your query
Read with this
Filter data
Filter data
More like this
Query code editor
Query code editor
Read with this
Accessing data tables
Accessing data tables
More like this