Hi, I’m new to graylog, I’ve seen a lot of topics on the subject without any real solution for my case.
1. Describe your incident:
I’m trying to create an Event Definition that should trigger ‘*’. However, despite having matching logs in the stream, the event definition returns no results, no matches, no notification.
2. Describe your environment:
-
OS Information: RHEL 9.5
-
Package Version: Graylog 6.1.6
Configuration :
See the Replay search finding logs :
Last mateched : Never
3. What steps have you already taken to try and solve the problem?
I’ve verified that the logs are correctly parsed and indexed, and I can manually search for them using the same query.
4. How can the community help?
Maybe I made a mistake? Is this a bug? Is this the graylog version?
Thank for your help