elasticsearch/esclean.py: use match for fleet field

Signed-off-by: Jakub Sokołowski <jakub@status.im>
This commit is contained in:
Jakub Sokołowski 2023-06-26 21:04:27 +02:00
parent dba844b9d3
commit 1e1228cd3a
No known key found for this signature in database
GPG Key ID: FE65CD384D5BF7B4
1 changed files with 1 additions and 1 deletions

View File

@ -71,7 +71,7 @@ def main():
elif opts.program:
queries.append({'term': {'program': opts.program}})
if opts.fleet:
queries.append({'term': {'fleet': opts.fleet}})
queries.append({'match': {'fleet': opts.fleet}})
if opts.severity:
queries.append({'term': {'severity_name': opts.severity}})
if opts.logsource_ip: