Whenever I specify a criteria to search against the
payload data, the results returns empty. I submitted a
query in the payload section for anything that has the
word "http" but results were null.
Browsing through the payload data I observed a least
400 alerts within the payload packet with that word
Is this a bug with 1.0.1 ?
Query written as
1. No encoding, No convert
2. (,has, http,) <- commas indicate fields