I'm trying to use a wildcard for the
message field but it doesn't seem to work. I'm trying to look for anything that starts with
async and filter them out.
message field, it can look like this:
async.channel.poolSize=0...so in kql, if I do something like
not message: "async*"....I still seem to get docs back that begin with async in the message field.