September 22, 2022, 4:34am
I’m not receiving windows logs, every time check alert there is exclamation next to graylog gl2_source_collector:35fac341-e225-44cb-8018-9973589a21f5 and says
Unknown field : Query contains unknown field: gl2_source_collector
Here is my configuration
Needed for Graylog
data: C:\Program Files\Graylog\sidecar\cache\winlogbeat\data
logs: C:\Program Files\Graylog\sidecar\logs
September 22, 2022, 4:49am
Hello && Welcome
What type did you use,
beats or beats (legacy) as your input?
September 22, 2022, 5:03am
I’m using beats 1.2 on graylog 4.3
September 22, 2022, 5:08am
I was referring to your INPUT being used. The 1.2 is sidecar version but that good to know.
You may need to post you sidecar.conf.
September 22, 2022, 5:12am
If you are available, please connect remote any desk. I’m using Beats not beats (deprecated ) it’s lab test before production deployment.
September 22, 2022, 12:58pm
my guess is that no log has been received yet.
Therefore the field (gl2_source_collector) is not indexed.
Maybe the command
graylog-sidecar -debug will help?
September 22, 2022, 3:48pm
Thanks I will try graylog-sidecar -debug
October 6, 2022, 3:49pm
This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.