I’m totally new here, so please bear with me.
I’m using Graylog 3.1.2 running on CentOS 8
I created an event as follows, and it does not fire, although I see the messages in the stream, and when I create the event I also see the message in the preview.
Beneath the summary of the event:
Title: Telenet modem disconnected
Description: Port down or line protocol down on switch1 in computer room 1 - Telenet modem
Filter & Aggregation
Search Query: source:“172.16.11.4:” AND message:“Interface GigabitEthernet1/0/26, changed state to down”
Streams: Cisco Switches
Search within: 2 minutes
Execute search every: 1 minutes
No Fields configured for Events based on this Definition.
Grace Period is set to 5 seconds
Notifications will include 1 messages