Unexpected results escaping characters in search queries
Posted: Mon Feb 26, 2018 5:25 pm
Searching a field for a string with a special character is not filtering the results to include the special character.
This is where I am entering the query I am expecting to get back all entries where the message field contains the text assignmentTotal:- instead it is returning all entries where the message filed contains the text assignmentTotal ignoring the :- portion
Here is an entry that is returned correctly The results though also include this entry I have tried many different variations to get this query to work but I cannot get the results I need.
Tested searches
Following queries return all entries with assignmentTotal ignoring :-
message:"assignmentTotal\:\-"
message:assignmentTotal\:-
message:assignmentTotal\:-
message:assignmentTotal\:\-
message:"assignmentTotal:-"
message:"assignmentTotal?\-"
message:"assignmentTotal\*\-"
message:"assignmentTotal\?\-"
message:"assignmentTotal*\-"
message:"assignmentTotal?-"
message:"assignmentTotal*-"
message:"assignmentTotal\?-"
message:"assignmentTotal\*-"
message:"assignmentTotal\?\-"
message:"assignmentTotal\*\-"
message:"assignmentTotal\?-"
message:"assignmentTotal\*-"
message:assignmentTotal\?\-
message:assignmentTotal\*\-
message:assignmentTotal\?-
message:assignmentTotal\*-
Following queries return no results
"message:assignmentTotal\:\-"
'message:assignmentTotal\:\-'
"message:assignmentTotal:-"
Following query returns QueryParsingException[[logstash-2018.01.27] Failed to parse query [message:assignmentTotal:-]]
message:assignmentTotal:-
Following query returns QueryParsingException[[logstash-2018.02.26] Failed to parse query [message:assignmentTotal:\-]]
message:assignmentTotal:\-
If anyone has any insight into what I am doing wrong I would appreciate the help.
This is where I am entering the query I am expecting to get back all entries where the message field contains the text assignmentTotal:- instead it is returning all entries where the message filed contains the text assignmentTotal ignoring the :- portion
Here is an entry that is returned correctly The results though also include this entry I have tried many different variations to get this query to work but I cannot get the results I need.
Tested searches
Following queries return all entries with assignmentTotal ignoring :-
message:"assignmentTotal\:\-"
message:assignmentTotal\:-
message:assignmentTotal\:-
message:assignmentTotal\:\-
message:"assignmentTotal:-"
message:"assignmentTotal?\-"
message:"assignmentTotal\*\-"
message:"assignmentTotal\?\-"
message:"assignmentTotal*\-"
message:"assignmentTotal?-"
message:"assignmentTotal*-"
message:"assignmentTotal\?-"
message:"assignmentTotal\*-"
message:"assignmentTotal\?\-"
message:"assignmentTotal\*\-"
message:"assignmentTotal\?-"
message:"assignmentTotal\*-"
message:assignmentTotal\?\-
message:assignmentTotal\*\-
message:assignmentTotal\?-
message:assignmentTotal\*-
Following queries return no results
"message:assignmentTotal\:\-"
'message:assignmentTotal\:\-'
"message:assignmentTotal:-"
Following query returns QueryParsingException[[logstash-2018.01.27] Failed to parse query [message:assignmentTotal:-]]
message:assignmentTotal:-
Following query returns QueryParsingException[[logstash-2018.02.26] Failed to parse query [message:assignmentTotal:\-]]
message:assignmentTotal:\-
If anyone has any insight into what I am doing wrong I would appreciate the help.