Skip to content

EQL: Wildcard matching doesn't work #53104

@costin

Description

@costin

With the execution engine hooked in, it seems that wildcard queries do not match anything:

process where process.name == "*" 

return no results. Remove the wildcard match or make it exact and results start streaming in.

Metadata

Metadata

Assignees

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions