Can’t search messages on Syslog UDP via rsylog (Loading without end )

Hi jan,

Thanks to reply me.
I do a snapshot on my VM .If I read my old messages a “jochen” I have to downgrade my Elasticsearch .
This version is Elasticsearch 5.6.10.
Before I downgrade I have to do :
1.sytemctl stop graylog-server.service
2.systemctl stop elasticsearch
3.delete file node in /var/lib/elasticsearch
4.remove rpm Elasticseactch 6.30 and install Elastisearch 5.6.10
5.sytemctl start elaasticsearch
6.sytemctl start graylog-server.service

it’s good methodolgy ?

I did get that you want to downgrade Elasticsearch, for that this should work as you wrote down.

It’s works.
Thanks jan the first time I think i had not delete my file before remove my elasticsearch.
Thanks jan and jochen for yours help.