Correct me if I’m wrong but are you searching in the YEAR of 2014? If so how are you retaining all your logs for that long?
I have Graylog 4.2 installed in my lab , unfortunately I could not reproduce your issue.
We are searching by the year 2014 for one of the queries and that one does work now. The issue I now have is I am trying to use timestamp as a variable in the search query itself. This may not be something that can be done we are trying to have a query that looks at the login time and records on a dashboard any time there is a login time past closing hours.
the query can be found below:
EventID:4624 AND timestamp:["*11:00" TO “*23:00”]