securityonion icon indicating copy to clipboard operation
securityonion copied to clipboard

FIX: Ensure Hunt pivots on "*Missing" fields use correct search

Open phil1090 opened this issue 2 years ago • 0 comments

The Hunt pivot on a missing field (from a multi-field aggregation) does not produce a useful search. For example, if the network.protocol field displayed "*Missing", pivots on the field would use the search "network.protocol:"*Missing"". That search should be "-_exists_:network.protocol".

phil1090 avatar May 27 '22 16:05 phil1090