How to Query for length with elasticsearch (KQL)

Painless is painfull :slight_smile: try this

{
  "script": {
    "script": {
      "lang": "painless",
      "source": "if (doc['zeek.dns.query'].size() == 0) { return false;} else {return doc['zeek.dns.query'].value.length() > 5;}"
    }
  }
}
2 Likes