One small correction, if I may: if submitOrder is a literal (constant), it should be surrounded by single quotes, not double ones: SELECT * FROM "alpha-*" where "APILog.req.operationName"='submitOrder'.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.