Decode_json_fields and when.not, not working as expected

I have the following simple when.not I am using for testing:

      - decode_json_fields:
              - equals.input.type: "docker"
          fields: ["log"]
          target: "log_json"
          process_array: true
          max_depth: 20

Although, I am still seeing events that have and input.type equal to "docker" being processed. Is this syntax correct? I am using an or here as a test as I will have more than one not condition once I get this simple one working.


@andrewkroh Do you maybe have some insights on this?

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.