Search filters
After specifying an index and time range, you can (and should, anywhere applicable) apply filters to reduce the number of returned events, and isolate the result set to just the events of interest.
The most-commonly used filters are to specify a sourcetype (which will typically reflect a particular log type, and data from numerous sources), followed by one or more field specifiers or text strings to search for. For example, the search string in the following figure returned events from the weblogs_90d_eidx index, where the sourcetype is access_combined, the status field contains values of 400 and above, and the event contains a text string of logins. This was for a search that covered the last 30 days; using this filtering ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access