You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The Hunt pivot on a missing field (from a multi-field aggregation) does not produce a useful search. For example, if the network.protocol field displayed "*Missing", pivots on the field would use the search "network.protocol:"*Missing"". That search should be "-_exists_:network.protocol".
Also applies to Acknowledgments, and any other query that is executed against a search result record.
The text was updated successfully, but these errors were encountered:
jertel
changed the title
FIX: Ensure Hunt pivots on "*Missing" fields use correct search
FIX: Ensure operations on records with "*Missing" fields use correct search
Dec 12, 2022
The Hunt pivot on a missing field (from a multi-field aggregation) does not produce a useful search. For example, if the network.protocol field displayed "*Missing", pivots on the field would use the search "network.protocol:"*Missing"". That search should be "-_exists_:network.protocol".
Also applies to Acknowledgments, and any other query that is executed against a search result record.
The text was updated successfully, but these errors were encountered: