Am i constructing this query correctly? I am getting an error when i return results but if i take out the filter it works fine.
GET indices*/_search
{
"sort": [
{
"@timestamp": {
"order": "desc"
}
}
],
"query": {
"bool": {
"must": [
{
"match_all": {}
}
],
"filter": [
{
"exists": {
"field": "event_data.TargetUserName"
}
},
{
"exists": {
"field": "event_data.ServiceName"
}
},
{
"match": {
"event_id": "4,769"
}
}
]
}
}
}