Thanks for reaching out! The search bar in the analytics exploration views expects a particular syntax.
For example, the OR case needs to be wrapped in parenthesis like (user.name: user1 OR user.name: user2)
Backslashes need to be escaped so the query might look like process.parent.executable : "C:\\Program Files (x86)\\Google\\Chrome\\Application\\chrome.exe"
Ah, sorry about that! In the OR query there needs to be no space between the field/value and the colon. So it would be (user.name:user1 OR user.name:user2) - apologies, I missed that the first time.
I'll double check on the escaping of backslashes and get back to you here. Thanks for your patience!
Just following up on the escaping of backslashes - apart from the extra space between the colon and the characters, the escaping looks right. Could you give it a try without the extra space?
Aha, omitting the spaces from the query does indeed work. Quite confusing that searching whatever does not work consistently between Kibana componenets imho.
Apologies for missing your last message. The backslashes in the example you showed looked right - it was the spaces that was the issue.
Regarding consistency in search syntax between components - you're right and we are making an effort to move toward that. It always helps to have specific examples like this so your message is much appreciated!
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.