I am using the Kibana 'filter builder' to create a search like 'uri is x'. The uri field (from Bro http logs) contains this: /auth/spGo.php?assetid=home&supportid=
When I set 'x' to one of these, the search works and finds what I expect (note lack of escaping):
/auth/spGo.php?assetid=home&supportid
/auth/spGo.php?assetid
spGo.php?assetid
When I set 'x' to one of these, the search does NOT work and finds nothing:
/auth/spGo.php?assetid=home&supporti
/auth/spGo.php?asseti
php?assetid
I would like to do search for ?, but using \? does not work either.
Sorry, by filter builder, I mean the "Add a filter +" just below the search box at the top of the "Discover" menu. I am sure there is an official name for this, but I do not know what it is. I have been looking at ELK for about a week and a half, so I have a lot to learn.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.