We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
For example, "NOT ET INFO", or !"ET INFO", doesn't do what you might expect it to.
The text was updated successfully, but these errors were encountered:
is there a workaround, to filter out a query string?
Sorry, something went wrong.
No, but have fix nearly done that should work with Elasticsearch and SQLite. It lets me create a query like:
dns -"et info" -"et dns"
to match all events containing dns, but exclude all those with et info or et dns. Would that work for your use cases?
dns
et info
et dns
search: bring back negated queries
525cf1d
Add query negations using '-'. For example a search like `-"SURICATA"` would would match events that don't contain SURICATA. #275
No branches or pull requests
For example, "NOT ET INFO", or !"ET INFO", doesn't do what you might expect it to.
The text was updated successfully, but these errors were encountered: