If you are on the Discover tab and you only have
* in the query bar, then you get results?
And on the left panel in Discover you have a field named "source" in the field list?
If you check on the Settings tab, click on your index pattern, and then it will show the list of fields. You can type
source in the filter bar to more quickly find the field if there's a lot.
Do you see a field named
_source and one named
And if you do have one named
source is it
indexed or just
If you only have
_source shown, then you would just put
/var/log/containers/greyhound-segment*.log in the query bar (not the
source: part and no double-quotes).
If you do have a
source field and it's analyzed, it would have split that log file path into individual fields on the slashes. So in that case you could try searching for
source: /var/log/containers/greyhound-segment*.log it will return every doc where source contains
If you really need to search on the full path, you would need an unanalyzed field like source.raw (maybe you saw that in your field list for this index?).
Here's a link to a page that explains it very well;