Hi, I am trying to perform a query like the following:
CommandLine :( "test" "test2") OR (CommandLine :( "token" "rpc") AND CommandLine :( "\: \:"))
Returns valid results because the word “token” has been found in the commandline, however there is no “::” within the commandline. So… why it return results?
If I remove “token” no result is received. In fact, if I search only for “:” or for “::”, escaping the colon with the backslash, there is no result (and if it should return results, such as those of the routes C: \ … what if contain a colon.)
Why is this behavior?
Appreciate any help
- Graylog 4.1
- MongoDB 4.2
- Elasticsearch 7
- Service logs, configuration, and environment variables: Sysmon logs