Skip to content

Add support for a mix of indexed fields and search-time fields - #5

Merged
eden881 merged 1 commit into
mainfrom
indexed-fields
Aug 6, 2026
Merged

eden881 merged 1 commit into
mainfrom
indexed-fields

Conversation

@eden881

@eden881 eden881 commented Aug 6, 2026

Copy link
Copy Markdown
Member

Add index-time extractions for low-cardinality fields on every sourcetype, keeping the existing search-time ones so Lynx AI can compare both paths on identical data. Indexed fields are copycat_-prefixed to avoid colliding with customer fields in the global fields.conf namespace.

@eden881 eden881 self-assigned this Aug 6, 2026
@eden881
eden881 requested a review from doronkg August 6, 2026 13:54

@doronkg doronkg left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, good catch on the prefix

@eden881
eden881 merged commit f8ebc98 into main Aug 6, 2026
1 check passed
@eden881
eden881 deleted the indexed-fields branch August 6, 2026 14:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants