I am trying to search the exchange logs in kibana. And sometimes there are some data just like:
2017-10-05 23:59:56 10.100.1.22 OPTIONS /Microsoft-Server-ActiveSync/default.eas - 443 hdqsmsg01\sjzznhf 126.96.36.199 - 401 1 1326 78
- will be a field means the field is empty, it will be indexed too. But I have not found a valid way to use filter to filter them. I have found that I can use
!ua: [* TO *] to search them.(assume the field name is ua) But it will not work in filter in kibana. Or may the way of the filter is not written correctly. And I am confused if the filed is an empty value or other? How to filter them?