Skip to content

Make kuery's use of implicit ANDs more clear #13563

@trevan

Description

@trevan

I used makelogs to generate some logstash data and then ran the query "extension:jpg response:404" under both kuery and lucene.

In kuery, it found 5 items. In lucene, it found 56 items. That is because kuery uses AND to join the clauses while lucene uses OR to join the clauses.

Since keury can be identical to lucene, I think you'll have confusion from people who switch between the two or are using filters that they found elsewhere.

I can't seem to find any reason why it was decided to use AND as the implicit join in either #12624 (PR) or #12624 (Issue) but maybe there was internal discussion about it.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions