In kibana, I want to see all results are the value of auditd.data.tty
is NOT equal to (none)
.
Is it possible to do such a query? Thanks ahead!
In kibana, I want to see all results are the value of auditd.data.tty
is NOT equal to (none)
.
Is it possible to do such a query? Thanks ahead!
Solved,
Had to be:
NOT auditd.data.tty: "(none)"
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.