I'm trying to search within a rawmessage field for a specific string but i get no results if the rawmessage is rather long. Is there a limit? Example:
rawmessage: device_id=bla [Root]system-notification-00257(traffic): start_time="2016-05-17 14:29:21" duration=0 policy_id=163 service=dns proto=17 src zone=zone dst zone=Uplink action=Permit sent=0 rcvd=0 src=188.8.131.52 dst=184.108.40.206 src_port=50633 dst_port=53 src-xlated ip=220.127.116.11 port=43614 dst-xlated ip=18.104.22.168 port=53 session_id=1983453 reason=Creation
Now when i search for "rawmessage: Creation" i get no hit. If the rawmessage is much shorter this generally works.
any hints would be really appreciated.
thanks and cheers