It looks close, does your query work if you remove the double quotes and close the single quote? .es(q='event_id=XXXX AND message:/WORD1|WORD2|WORD3|WORD4/')
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.