Hello guys, I am new here an fairly new to actually using Kibana for searching data and creating visualization board.
I am tasked to Query logs to find out is a sessionID is in plaintext, I am running into problem creating a query that will do just that.
As the sessionID is located in a field called message which has numerous of fields.
The first thing i need to do is to get a handle on the sessionID field in the message body then I need to check if the field is Plaintext vs Ciphertext which also poses a problem.
- How do I drilled down to match a specific field with a message body ?
- How would a check the value to see if the value is displaying plaintext ?