How to search logs with graylog


#1

Hi,

i use the graysquid Input in order to collect the squid’s logs, but when i want to search a log which contain the string of caracters “cucumber”, there a message in Search, fields : message : Analysis features for this field have been disabled by the administrator.

how to enable it ?

Thanks you by advance


(Jan Doberstein) #2
  • What exactly is your search string?
  • What Elasticsearch Version did you have?

#3

Re,

What exactly is your search string ?
It’s the domain-name of an website, exemple : www.google.fr

My Elasticsearch version :
elasticsearch-5.6.9-1.noarch


(Jan Doberstein) #4

@flo so you just type in

www.google.fr

in the search field of Graylog?


#5

Oh thanks a lot i found the research bouton ! :smiley:

Now i would like to search a keyword with regular expression like : google
Because your solution works only with complete domain-name: www.google.fr

(sorry for my bad english)


(Jochen) #6

The “Filter Fields” text input only filters available message fields, e. g. you could enter “appl” and it would show the “application_name” field.

If you want to search field contents, you’ll have to use the search input on top (next to the green button with the white magnifying glass).


(system) #7

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.