Sort the columns displayed by the order you select the fields in event type definition.
Before they were displayed in the order elastic returned them in json object. But Json order is random.
This creates a new array in order of the fields an passes it to extractFields function.
If there is a dot in fieldname i assume that the content is an array (for example geoip.countryname, geoip.ip, etc.).
Sort the columns displayed by the order you select the fields in event type definition. Before they were displayed in the order elastic returned them in json object. But Json order is random. This creates a new array in order of the fields an passes it to extractFields function. If there is a dot in fieldname i assume that the content is an array (for example geoip.countryname, geoip.ip, etc.).