I'm running ELK 6.2.2 with winlogbeat and collect sysmon logs.
When I'm trying to run a search query against event_data.CommandLine that looks like following:
I get no matches.
If I run:
it successfully returns records which contain mentioned cmdlet in the entire message field.
Also, I can find what I look for using:
As I understood from the available docs, the event_data.* fields are computed by elastic on the fly and therefore unsearchable using phrase matching. Is there a way to make them searchable?
Now, I consider mapping in logstash from event_data.X => X for selected fields.
Thanks for help!