Dear all =)
Ideally would I like to make a search query that contains approx 100
OR operators and 1
AND NOT like so
(logLevel:error OR logLevel:fatal) AND NOT (searchString1 OR searchString2 OR searchString3 OR ... OR searchString100)
searchString would typically be simple such as
msg:'Could not find ID' but with approx 100 different messages.
I want to find all the errors I don't know how to search for. All the
searchString's are error messages I know about, so the purpose of this is to create a "Catch All" =)
Which raises the following questions =)
- Is there a max number of operators in a query? 500 would be excellent if possible =)
- Will this be CPU heavy on Elastic?
- Are there a better way to do it?