arkime / arkime

Arkime is an open source, large scale, full packet capturing, indexing, and database system.
https://arkime.com
Apache License 2.0
6.26k stars 1.04k forks source link

Multies and tag searches #231

Closed ghost closed 10 years ago

ghost commented 10 years ago

Searches using "tags == " bring back no results using Multies.

Apr 15 16:24:23 server01 moloch-mviewer: sessions.json query {"from":"0","size":100,"query":{"filtered":{"query":{"range":{"lp":{"from":1397575455}}},"filter":{"term":{"ta":"protocol:dns"}}}},"facets":{"dbHisto":{"histogram":{"key_field":"lp","value_field":"db","interval":60,"size":1440}},"paHisto":{"histogram":{"key_field":"lp","value_field":"pa","interval":60,"size":1440}},"map1":{"terms":{"field":"g1","size":1000}},"map2":{"terms":{"field":"g2","size":1000}}},"sort":[{"fp":{"order":"asc"}},{"fpd":{"order":"asc"}}],"fields":["pr","ro","db","fp","lp","a1","p1","a2","p2","pa","by","no","us","g1","g2","esub","esrc","edst","efn","dnsho","tls","ircch"]}

awick commented 10 years ago

Need to do viewer regression scripts like I have for capture :)

eoinmiller commented 10 years ago

You said you hated that!

awick commented 10 years ago

i hate everything