I recently set up ZIA integration with Elastic agent, we are getting the Datastreams but are unable to search for anything, anything comes back with no results , verified default template and all fields are keywords but if i do a Filter , it works .
You just cant search for a keyword in the KQL syntax
Can you share exactly what you are trying to do? Please share some screenshots for example.
Full-text search is done on fields that are mapped as texted, the majority of fields do not need to be mapped as text because they contain just keywords, so they are mapped as keywords.
Keywords fields need to be search for the exact match, case sensitive, or for part of it using wildcards.
example .this Document has the country of PL, i want to free text search for all documents from PL. 0 reults come back . Note all fields are keywords as these are datastreams from ZIA integration
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.