Hi all,
I've got an ES cluster that contains a heap of AWS events. One of the main fields I would like to search on is eventSource. In Kibana I have a number of filters saved, one of them is:
eventSource:s3.amazonaws.com
When I run this search in the discover field, I also get results for ec2.amazonaws.com which I don't understand. If I wrap the query string in double quotes, such as:
eventSource:"s3.amazonaws.com"
The filter works correctly. Now that I've got it to work, I'd like to understand why the quotes are necessary? Looking at:
eventSource:s3.amazonaws.com
and
eventSource:ec2.amazonaws.com
I don't understand why quotes would be required, can anyone shed some light on the cause?
Thanks!