So I'm looking to pull EVENT.DURATION out of the Logstash IIS preloaded filter. That's all in place and pulling fine.
However, you'll notice that it's pulling as an int, which is exactly what I want. The weird part is, I can't seem to pull ANYTHING when I ask to grab log entries below a certain level (remove the downtime pieces)
When I ask for event.duration < 4000 I get exclusively 0.0's back. When I add "And event.duration > 0.0" I get nothing back at all.
Any Idea's what's happening here?