Need help in search query

(Blason) #1

Hi team,

My message being parsed as follows

1 method=GET url= sent=/var/lib/inetsim/http/fakefiles/sample.doc postdata

I need to set up a query where if rest_message field contains “url=” but dang I am unable to match those out. Can someone please help?

(Blason) #2

Ah …got the answer

Also note that message , full_message , and source are the only fields that are being analyzed by default. While wildcard searches (using * and ? ) work on all indexed fields, analyzed fields will behave a little bit different. See wildcard and regexp queries for details.

(Tess) #3

Care to share that answer with the rest? :wink: Somebody else could learn from it :slight_smile:

(Blason) #4

That is been shared!! see my response

You need to enable wildcard searches in server.conf file.

