I try to filter for a "-" in winlog.event_data.SidHistory field (logs from winlogbeat). I have 7.2 ELK Stack.
Filtering with filters from graphical interface simply doesn't work
Kibana will show "-" for empty or null. If you get a chance to expand the table and click on the JSON tab, can you check what the raw value for the field is? We may be able to use the "is empty" filter.
I check the answer in JSON (Inspect->Response) and it is "-" value.
By the way, i use all possible filters and it still doesn't work. Also i use (Zoom out) icon - so i think it must exclude SidHistory, whatever value it has..
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.