I have green state (
curl _cat/indices?v, system overview) on the graylog multi node setup.
I have 10 hosts which send his logging activity (SSH) to a TCP Syslog Input.
I see it on the right top page (In/out eps) but when I search it, no result.
- With the classic research request;
- With the Input search button (with
When I force the new event, I check with
curl _cat/indices?v, I see the
docs.count up (example: 3639, generate SSH event on one host, 3650 after.)
Someone have an idea ?