Please help me with Graylog Sidecar and Winlogbeat. I’m filtering Windows logs by the log_level: [critial, error, warning] field, but it’s not filtering. I’ve tried without the quotes and it’s not working. How do I filter Windows logs by severity level? I’m using the latest version of Graylog 6.3.1.
Hello @Pamela,
How do the log messages appear within the Graylog UI?
If the query is to be used within Graylog it should
log_level:(critial OR error OR warning)