I used a wildcard field in my index mapping in order to be able to use wilcard in my logs.
Now, I try to select some lines in my logs which begins with "Request finished"
it is working but there are too much results for me
message:Request finished* or message:"Request finished*" or message:Request finished or message:Request?finished*
=> expand your time range...
the only way I find is to deactivating KQL and using this Lucene syntax
Do you see a way to search it easilly trought KQL ?
Exemple of message I want to match :
Request finished HTTP/1.1 GET http://staging-wmsdevplatform.fmlogistic.fr:5000/api/Size/GetSupportQuantity?activityCode=SDO&depositCode=ECR&supportNumber=336042896110201330 application/json - - 404 0 - 17.1080ms