It's possible you need to escape the %, based on how you've indexed your data. I assume the issue is caused by how your data is indexed in elasticsearch. Checkout [1] for similar question
Spencer, thanks for responding. I read the link but I don't understand how thats supposed to help me. I see the % character when I search for messages by hostname, ie; syslog_hostname:sw-001
Sep 8 23:26:34 sw-001 1577: 17w1d: %SYS-5-CONFIG_I: Configured from console by user on vty0 (192.168.15.7)
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.