Hello,
how should I write query with colon in search value?
{"size":0,"_source":["attrs.from"],
"query":{"bool":{"must":[
{"range":{"@timestamp":{"gte":1554792885000,"lte":1554814485000,"format":"epoch_millis"}}},
{"query_string":{"query":"attrs.r-
uri:sip\\:example.org","analyze_wildcard":true,"fuzzy_max_expansions":0,"fuzziness":0}},
]}},
"aggs":{"agg":{"date_histogram":
{"field":"@timestamp","interval":"5m","time_zone":"Europe/Berlin","min_doc_count":1},
"aggs":{"agg":{"terms":{"field":"attrs.type","size":30,"order":{"_count":"desc"}}}}}}}.
As you can see I was trying to use uri:sip\\:example.org
or uri:sip\:example.org
but no success so far