Logs by severity level

Please help me with Graylog Sidecar and Winlogbeat. I’m filtering Windows logs by the log_level: [critial, error, warning] field, but it’s not filtering. I’ve tried without the quotes and it’s not working. How do I filter Windows logs by severity level? I’m using the latest version of Graylog 6.3.1.

Hello @Pamela,

How do the log messages appear within the Graylog UI?

If the query is to be used within Graylog it should

log_level:(critial OR error OR warning)