@@ -132,43 +132,43 @@ process where process_name == "python.exe" or process_name == "SMSS.exe" or proc
132132multipleOrAndEquals_As_InTranslation
133133process where process_name == "python.exe" and process_name == "SMSS.exe" or process_name == "explorer.exe" or process_name == "test.exe"
134134;
135- {"bool":{"should":[{"bool":{"must":[{"term":{"process_name":{"value":"python.exe"}}},{"term":{"process_name":{"value":"SMSS.exe"}}}],"boost":1}},{"terms":{"process_name":["explorer.exe","test.exe"],"boost":1}}],"boost":1}}
135+ {"bool":{"should":[{"bool":{"must":[{"term":{"process_name":{"value":"python.exe"}}},{"term":{"process_name":{"value":"SMSS.exe"}}}],"boost":1.0 }},{"terms":{"process_name":["explorer.exe","test.exe"],"boost":1.0 }}],"boost":1.0 }}
136136;
137137
138138mutipleOrEquals_As_InTranslation2
139139process where source_address == "123.12.1.1" or (opcode == 123 or opcode == 127)
140140;
141- {"bool":{"should":[{"term":{"source_address":{"value":"123.12.1.1"}}},{"terms":{"opcode":[123,127],"boost":1}}],"boost":1}}
141+ {"bool":{"should":[{"term":{"source_address":{"value":"123.12.1.1"}}},{"terms":{"opcode":[123,127],"boost":1.0 }}],"boost":1.0 }}
142142;
143143
144144mutipleOrEquals_As_InTranslation3
145145process where (source_address == "123.12.1.1" or source_address == "127.0.0.1") and (opcode == 123 or opcode == 127)
146146;
147- {"bool":{"should":[{"term":{"source_address":{"value":"123.12.1.1"}}},{"terms ":{"opcode":[123, 127],"boost":1}} ],"boost":1}}
147+ {"bool":{"should":[{"term":{"source_address":{"value":"123.12.1.1"}}},{"term ":{"source_address":{"value":" 127.0.0.1"}}} ],"boost":1.0}},{"terms":{"opcode":[123,127 ],"boost":1.0 }}
148148;
149149
150150mutipleOrEquals_As_InTranslation4
151151process where (source_address == "123.12.1.1" or source_address == "127.0.0.1") and (opcode == 123 or opcode == 127)
152152;
153- "must":[{"bool":{"should":[{"term":{"source_address":{"value":"123.12.1.1"}}},{"term":{"source_address":{"value":"127.0.0.1"}}}],"boost":1}},{"terms":{"opcode":[123,127],"boost":1}},{"term":{"event.category":{"value":"process"}}}]
153+ "must":[{"bool":{"should":[{"term":{"source_address":{"value":"123.12.1.1"}}},{"term":{"source_address":{"value":"127.0.0.1"}}}],"boost":1.0 }},{"terms":{"opcode":[123,127],"boost":1.0 }},{"term":{"event.category":{"value":"process"}}}]
154154;
155155
156156multipleOrIncompatibleTypes1
157157process where process_name == "python.exe" or process_name == 2 or process_name == "3"
158158;
159- {"bool":{"should":[{"term":{"process_name":{"value":"python.exe"}}},{"term":{"process_name":{"value":2}}},{"term":{"process_name":{"value":"3"}}}],"boost":1}}
159+ {"bool":{"should":[{"term":{"process_name":{"value":"python.exe"}}},{"term":{"process_name":{"value":2}}},{"term":{"process_name":{"value":"3"}}}],"boost":1.0 }}
160160;
161161
162162multipleOrIncompatibleTypes2
163163process where process_name == "1" or process_name == 2 or process_name == "3"
164164;
165- {"bool":{"should":[{"term":{"process_name":{"value":"1"}}},{"term":{"process_name":{"value":2}}},{"term":{"process_name":{"value":"3"}}}],"boost":1}}
165+ {"bool":{"should":[{"term":{"process_name":{"value":"1"}}},{"term":{"process_name":{"value":2}}},{"term":{"process_name":{"value":"3"}}}],"boost":1.0 }}
166166;
167167
168168multipleOrIncompatibleTypes3
169169process where process_name == 1.2 or process_name == 2 or process_name == "3"
170170;
171- {"bool":{"should":[{"term":{"process_name":{"value":1.2}}},{"term":{"process_name":{"value":2}}},{"term":{"process_name":{"value":"3"}}}],"boost":1}}
171+ {"bool":{"should":[{"term":{"process_name":{"value":1.2}}},{"term":{"process_name":{"value":2}}},{"term":{"process_name":{"value":"3"}}}],"boost":1.0 }}
172172;
173173
174174// this query as an equivalent with
@@ -177,7 +177,7 @@ process where process_name == 1.2 or process_name == 2 or process_name == "3"
177177multipleOrIncompatibleTypes4
178178process where process_name == 1.2 or process_name == 2 or process_name == 3
179179;
180- {"bool":{"should":[{"term":{"process_name":{"value":1.2}}},{"term":{"process_name":{"value":2}}},{"term":{"process_name":{"value":3}}}],"boost":1}}
180+ {"bool":{"should":[{"term":{"process_name":{"value":1.2}}},{"term":{"process_name":{"value":2}}},{"term":{"process_name":{"value":3}}}],"boost":1.0 }}
181181;
182182
183183// this query as an equivalent with
@@ -186,25 +186,25 @@ process where process_name == 1.2 or process_name == 2 or process_name == 3
186186multipleOrIncompatibleTypes5
187187process where source_address == "123.12.1.1" or source_address == "123.12.1.2"
188188;
189- {"bool":{"should":[{"term":{"source_address":{"value":"123.12.1.1"}}},{"term":{"source_address":{"value":"123.12.1.2"}}}],"boost":1}}
189+ {"bool":{"should":[{"term":{"source_address":{"value":"123.12.1.1"}}},{"term":{"source_address":{"value":"123.12.1.2"}}}],"boost":1.0 }}
190190;
191191
192192multipleOrIncompatibleTypes6
193193process where source_address == "123.12.1.1" or source_address == concat("123.12.","1.2")
194194;
195- {"bool":{"should":[{"term":{"source_address":{"value":"123.12.1.1"}}},{"term":{"source_address":{"value":"123.12.1.2"}}}],"boost":1}}
195+ {"bool":{"should":[{"term":{"source_address":{"value":"123.12.1.1"}}},{"term":{"source_address":{"value":"123.12.1.2"}}}],"boost":1.0 }}
196196;
197197
198198multipleOrIncompatibleTypes7
199199process where source_address == "123.12.1.1" and (source_address == "123.12.1.2" or source_address >= "127.0.0.1")
200200;
201- "must":[{"term":{"source_address":{"value":"123.12.1.1"}}},{"bool":{"should":[{"term":{"source_address":{"value":"123.12.1.2"}}},{"range":{"source_address":{"gte":"127.0.0.1","boost":1}}}],"boost":1}},{"term":{"event.category":{"value":"process"}}}]
201+ "must":[{"term":{"source_address":{"value":"123.12.1.1"}}},{"bool":{"should":[{"term":{"source_address":{"value":"123.12.1.2"}}},{"range":{"source_address":{"gte":"127.0.0.1","boost":1.0 }}}],"boost":1.0 }},{"term":{"event.category":{"value":"process"}}}]
202202;
203203
204204multipleOrIncompatibleTypes8
205205process where source_address == "123.12.1.1" and (source_address == "123.12.1.2" or source_address == "127.0.0.1")
206206;
207- "must":[{"term":{"source_address":{"value":"123.12.1.1"}}},{"bool":{"should":[{"term":{"source_address":{"value":"123.12.1.2"}}},{"term":{"source_address":{"value":"127.0.0.1"}}}],"boost":1}},{"term":{"event.category":{"value":"process"}}}]
207+ "must":[{"term":{"source_address":{"value":"123.12.1.1"}}},{"bool":{"should":[{"term":{"source_address":{"value":"123.12.1.2"}}},{"term":{"source_address":{"value":"127.0.0.1"}}}],"boost":1.0 }},{"term":{"event.category":{"value":"process"}}}]
208208;
209209
210210inFilterWithScripting
0 commit comments