in both api endpoints, we have parameters that we can use to specify the timerange of logs that we want to get. In the first endpoint, we have to and from and in the second api endpoint we have range parameter.
I’m sending the parameters in the correct format, but I get all logs back. Can someone help me with? or am i missing something? I’m trying to get logs for a single day. No matter what i send, i get all logs.
Can you share your API query you are sending? You can redact any info you need but that will help. What is the range parameter? I don’t see that as a valid parameter.
Your screenshot shows from/to as 9/25 - 9/26. But in your description you stated 9/25 - 8/15, which seems to match what you are getting back. Can you double-check?
As Drew said, to properly diagnose please paste the specific queries that are being sent.
Can you please show me the query that you’re sending? Are there any other settings that i should be familiar with because i have tried multiple times and I’ll show you again. Using graylog 4.2. Plus attaching one more demo of of the issue along with the request.
The creation timestamp of a message is distinct from the ingestion timestamp (though you can override ingestion timestamp via extractor or pipeline rule). Search is based on ingestion time. Maybe that explains the discrepancy.