# Log filtering a field re-ordering

**URL:** <https://community.zeek.org/t/log-filtering-a-field-re-ordering/3502>\
**Category:** Zeek\
**Created:** [February 26, 2015, 6:26pm UTC](https://community.zeek.org/t/log-filtering-a-field-re-ordering/3502 "2015-02-26T18:26:27Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Eric\_Howard](https://avatars.discourse-cdn.com/v4/letter/e/e95f7d/32.png) [@Eric\_Howard](https://community.zeek.org/u/Eric_Howard)\
**Post date:** [February 26, 2015, 6:26pm UTC](https://community.zeek.org/t/log-filtering-a-field-re-ordering/3502/1 "2015-02-26T18:26:27Z")

</div>

Hi all, I have followed the instructions contained in [https://www.bro.org/sphinx-git/frameworks/logging.html#filtering](https://www.bro.org/sphinx-git/frameworks/logging.html#filtering) to create a new field output. I ahve noticed that the fields you choose to include cannot be be re-ordered for display. For example, if I put the ‘ts’ field in the first position like this:

```auto
local filter: Log::Filter = [$name="orig-only", $path="origs", $include=set("id.orig_h","ts")];

```

the record displays with it in the first position. I assume this is because the include set is just a toggle that does not affect display order which is based on the field position in INFO. How to I re-order the the fields for display? Is this done ion the writer?

Thanks!

– Eric –

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:42pm UTC](https://community.zeek.org/t/log-filtering-a-field-re-ordering/3502/2 "2022-05-06T15:42:29Z")

</div>


