Page MenuHomePhabricator

meta.domain in Logstash seems to usually not like doing term matches
Open, Needs TriagePublic


Using a filter bubble like "meta.domain is one of (,," yields no results currently. It's be great if this worked based on e.g. simple term matching so that it includes e.g. and

I thought maybe the issue is that the "one of" operator doesn't do term matching but that "is" does, however, `meta.domain is" also yielded zero results.

Then I entered "meta.domain is org" and that did yield results from various third-party domains that ended in .org, such as

Event Timeline

You will need to search against an un-analyzed field to get the kind of matching you are hoping for. I think the meta.domain.keyword might be what you need.

For the record, @bd808 and I tried that, but it didn't work and failed in the same way.