Update docs for non-indexed match type filters

This commit is contained in:
armirveliaj
2025-07-11 04:56:47 -04:00
committed by Dan Christian Bogos
parent 379f467ff7
commit 319a4f9cf3
2 changed files with 17 additions and 0 deletions

View File

@@ -54,18 +54,28 @@ The following types are implemented:
\*notstring
Is the negation of *\*string*.
\*nistring
Non-indexed version of *\*string*. Bypasses field indexing.
\*prefix
Will match at beginning of *Element* one of the values defined inside *Values*.
\*notprefix
Is the negation of *\*prefix*.
\*niprefix
Non-indexed version of *\*prefix*. Bypasses field indexing.
\*suffix
Will match at end of *Element* one of the values defined inside *Values*.
\*notsuffix*
Is the negation of *\*suffix*.
\*nisuffix*
Non-indexed version of *\*suffix*.. Bypasses field indexing.
\*empty
Will make sure that *Element* is empty or it does not exist in the event.
@@ -78,6 +88,9 @@ The following types are implemented:
\*notexists
Is the negation of *\*exists*.
\*niexists
Non-indexed version of *\*exists*. Bypasses field indexing.
\*timings
Will compare the time contained in *Element* with one of the TimingIDs defined in Values.