where
Keeps only events for which the given predicate is true.
Description
The where
operator only keeps events that match the provided predicate and
discards all other events. Only events for which it evaluates to true
pass.
Keeps only events for which the given predicate is true.
The where
operator only keeps events that match the provided predicate and
discards all other events. Only events for which it evaluates to true
pass.
src_ip
is 1.2.3.4
ts
field