securityonion
securityonion copied to clipboard
FIX: Ensure Hunt pivots on "*Missing" fields use correct search
The Hunt pivot on a missing field (from a multi-field aggregation) does not produce a useful search. For example, if the network.protocol field displayed "*Missing", pivots on the field would use the search "network.protocol:"*Missing"". That search should be "-_exists_:network.protocol".