Messages going in, but All Messages steam view is empty

Description of your problem

I have a data feeding into an input, but when I view the All Messages stream, the dashboard has no data.

Description of steps you’ve taken to attempt to solve the issue

I checked Show Received Messages in the Inputs page, and messages are shown

Environmental information

Operating system information

Ubuntu 20.04

Package versions

  • Graylog 4.1.3
  • MongoDB 3.6.8
  • Elasticsearch 7.14.0

New users here can only add one embedded image per post, so I had to ass the screenshot of the All Messages stream here.

Hello @seanthegeek, welcome!

The is usually due to a time/time zone misconfiguration. Try expanding your search window by however many hours are between you and GMT+/-1. So, for me that would be from “now” until 6 hours in the future.

Alternatively, check your input message buffer and disk journal on the nodes page to make sure messages aren’t backing up in the queue/s for some reason.

Yep. it was a time zone issue. The firewall was configured for local time, but the input was configured for UTC. I’ll change the firewall config to log in UTC. Thanks!

On a side note your Elasticsearch 7.14 is beyond the supported version of 7.10 so you may see some other anomalies.

