Rule filter seems to be picking up on query_string values, not term values #1529
-
This is my filter:
The filter seems to be working for everything except the last two terms:
Meaning it is excluding all the above queries but not the last two terms. Any idea what the fix is? |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
Perhaps the geoip.region_name field isn't matching the actual field, due to it being an object vs a field name with periods in it. Any time I have an issue like this I use the Kibana interface, with the Inspect panel, to compare how Kibana builds the filter vs how I write in my rule. If it works in Kibana I would replace my rule filter with the Kibana inspection syntax. |
Beta Was this translation helpful? Give feedback.
This seems to be the fix (it doesn't give the ability to restrict by the specific field but for my use-case it doesn't matter):
So just putting it in…