Open frack113 opened 3 months ago
What use case does this solve that |exists
doesn't? IIRC most SIEMs I used cannot discriminate between a field existing and a field existing and having the null
value. What are some examples of SIEMs that have this feature, and why would one want to use that instead of |exists
?
Add a new modifer to check if the field data is empty or null. Some telemetry use
-
toowill cover