I am logging messages in Graylog2 and I need to evaluate messages based on the order they arrive.
Upon making a search Graylog presents me the information ordered by Timestamp, which is very useful:
As you can see there are 2 types of timestamps marked:
- The Timestamps on the left, in descending order, given by Graylog2
- A unique timestamp ( on the right, I just marked the first one, the others I don’t care ) for each message
So, after visualizing this data, I decided I wanted to export it to CSV format, to run a few scripts on it. I did the following:
More actions .-> Export as CSV
The probem here is that the CSV file I have, is completely unordered. Remeber the unique timestamp on the right that I marked with yellow color?
It should be in the first row, but it’s not:
It is in row 188.
- Is this normal behavior?
- How to export a search to a CSV keeping its filters and order intact?