Sample Log
16/Jan/2021:00:00:01 +0000 1111155317 madridES_20 90.180.XX.167 GET https www.cdn77.com /img/customers_logos_light.png 200 HIT 35532 41004 0.000 424923 Mozilla/5.0 (Linux; Android 4.4.2; SUNSET Build/KOT49H) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/47.0.2526.83 Mobile Safari https://www.cdn77.com/css/main.min.css V3
How Bloom filters work when written in quotes like this 1st Query -
index=some_index "Mobile Safari"
As per my understanding terms in logs break on major segmenters i.e. space here and make lexicon terms that are present in tsidx files on which bloom filters work. If I write the query like this
2nd Query -
index=some_index TERM(Mobile Safari)
It won't return any events as there is no Lexicon Term present in tsidx files like Mobile Safari as a whole. But the 1st query is returning the events having the string Mobile Safari. I want to understand how filter in double quotes is different from the one used inside TERM. How these filters are processed?
... View more