Hi,
I use API to get logs from graylog. root_timezone is set in config file. And in GUI everything is ok, graylog timestamp = timestamp in log. Unfortunately API query is processed with UTC time zone.I use admin account to authenticate in API. What do I do wrong?
API query:
“{ “streams”: [ “603f6b27862c625f00730877” ], “timerange”: [“absolute”, { “from”: “2021-04-02T07:50:00.000Z”, “to”: “2021-04-02T07:59:59.999Z” }] , “query_string”: { “type”:“elasticsearch”, “query_string”:“action:accept AND subtype:forward AND dstintf:port10” } }”
Best regards,
Lukasz