Hello guys, i copied the configuration of a present graylog to a new graylog(latest version). I discovered that after dividing them into streams, some streams open immediately and show logs while the others stay for hours without displaying logs. And i have an average of 200-250 logs per second. Attached to this message is the screenshot of the logs not displaying despite the high log influx.
am sorry i dont get the question. But if you meant what logs am i forwarding to graylog…logs from the devices i would like to monitor.(windows,AV,FW and proxy)
It was very easy. you know i mentioned that i transferred the configuration from the former graylog server to a new one. It was referencing fields that have been deleted.