I’m not receiving linux logs,with filebeat
every time check alert there is exclamation next to graylog
gl2_source_collector:3158f974-c860-4765-ac89-4454a5516eff and says Unknown field: Query contains unknown field: gl2_source_collector
time/date is currecrt.
i use graylog-sidecar -debug but i have not error or warning.
linux client has ping graylog server.
linux client send log with rsyslog to graylog server but do not send log with filebeat.
filebeat is start on linux client.
graylog sidecar is start on linux client.
please help me.
On your Graylog Sidecar dashboard does the collector Status show running? I would imagine that if GL sidecar is not working then the field (i.e., gl2_source_collector) would not be present.
thank you for reply.
i remove graylog 5 and install graylog 4 .
I use * on graylog 4 , gray log show me error Query parsing error: Cannot parse query, cause: ‘*’ or ‘?’ not allowed as first character in WildcardQuery.
This is very strange. I did everything according to the graylog document, but even though I changed the versions, I still have a problem.