Thanks for the reply. I'd already tried that particular syntax but still no luck. The full filter is shown below. I'm essentially pulling in a txt file as a key/value pair, mutating some of it and pushing it to Elastic. The UserName field contains either the PC name and the username separated by a \ or the domain name and username in the same format.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.