Help with term filter #1113
-
Hi - I need assistance with this the following filter
What I desire is to filter for logs that have ":3389" at the end of the dst port but also a usr field that contains a value (meaning it can't be empty). So basically a dst port with :3398 AND an existing user in the usr field will cause an alert hit. Can you help with the syntax if what I have so far is not correct? |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 2 replies
-
This is more of an elasticsearch question since it's focused on Elastic/Lucene query syntax. This link may help you: https://discuss.elastic.co/t/elastic-search-query-to-check-if-property-is-empty-non-empty/308290 |
Beta Was this translation helpful? Give feedback.
This is more of an elasticsearch question since it's focused on Elastic/Lucene query syntax. This link may help you: https://discuss.elastic.co/t/elastic-search-query-to-check-if-property-is-empty-non-empty/308290