# Help Creating Stream

**URL:** <https://community.graylog.org/t/help-creating-stream/9644>\
**Category:** Graylog Central (peer support)\
**Created:** [March 26, 2019, 5:33pm UTC](https://community.graylog.org/t/help-creating-stream/9644 "2019-03-26T17:33:54Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![lissaware](https://avatars.discourse-cdn.com/v4/letter/l/e19adc/32.png) [@lissaware](https://community.graylog.org/u/lissaware)\
**Post date:** [March 26, 2019, 5:33pm UTC](https://community.graylog.org/t/help-creating-stream/9644/1 "2019-03-26T17:33:54Z")

</div>

I’m trying to create a stream for this search query

```
identity:ams_production level: 3 AND message: 'AmsAusLiveToVodStatusShellJob Live To Vod Converting failed or deleted'

```

> **[Screenshot](https://prnt.sc/n393oj)**
>
> Captured with Lightshot

and for my stream rules I have the fallowing options;

```
* Field *identity* must match exactly *ams_production*
* Field *level* must be smaller than *3*
* Field *message* must not match exactly *'AmsAusLiveToVodStatusShellJob Live To Vod Converting failed or deleted'*

```

> **[Screenshot](https://prnt.sc/n394i9)**
>
> Captured with Lightshot

The stream is not display any of the data from the original search query under the stream. What am I missing?

---

<div class="post-metadata">

**Author:** ![macko003](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/macko003/32/3175_2.png) [@macko003](https://community.graylog.org/u/macko003)\
**Post date:** [March 26, 2019, 6:12pm UTC](https://community.graylog.org/t/help-creating-stream/9644/2 "2019-03-26T18:12:18Z")

</div>

Do it one by one.  
Do three stream for every rule, and you Will find the error.

---

<div class="post-metadata">

**Author:** ![lissaware](https://avatars.discourse-cdn.com/v4/letter/l/e19adc/32.png) [@lissaware](https://community.graylog.org/u/lissaware)\
**Post date:** [March 26, 2019, 6:32pm UTC](https://community.graylog.org/t/help-creating-stream/9644/3 "2019-03-26T18:32:32Z")

</div>

I have tried and for whatever reason none of them are showing the correct rules.

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [March 27, 2019, 7:13am UTC](https://community.graylog.org/t/help-creating-stream/9644/4 "2019-03-27T07:13:16Z")

</div>

first it isn’t that nice to post the same question over different places …

> **[r/sysadmin - Graylog Help Creating Stream](https://www.reddit.com/r/sysadmin/comments/b5vr3v/graylog_help_creating_stream)**
>
> 0 votes and 2 comments so far on Reddit

(and not connect the posts to each other )

Your search in the first screenshot is not what you like to get into your stream. In addition you did not show the expanded message - so no idea if the messages have the fields or not.

Having a full sentence match like you have in your last rule is a bad idea, just for performance reasons. Every messages will run into this regex and will be checked on that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [April 10, 2019, 7:13am UTC](https://community.graylog.org/t/help-creating-stream/9644/5 "2019-04-10T07:13:18Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
