(2016-06-07)
Problem
I have a standard stream of sendmail logs that are being streamed into Elasticsearch more or less unfiltered using only
match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{GREEDYDATA:syslog_message}" }
...way of doing things.
I want to search the resulting indexes for a particular email address.
Solution
To search for dave@xdroop.com, query for:
dave AND @xdroop.comThis is a hack but it should return what you want. (Maybe with lots of stuff you don't want, I don't know. But at least I can find it now.)