Skip to content

how to query nested value in elastalert2 using query_strings #1089

Locked Answered by jertel
ziaul-ict2020 asked this question in Q&A
Discussion options

You must be logged in to vote

On this line:

      query: "http.url: https://hidden AND http.response_code: 200"

Try wrapping the URL value in escaped quotes:

      query: "http.url: \"https://hidden\" AND http.response_code: 200"

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by jertel
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants