Do you send the logs to elasticsearch instead of graylog?
If graylog doesn’t process a message, it won’t show it.
If you check your message there are no “gl2_”* field in it.
Am I correct?
oh, it’s easier. Check the date in the sent message, and at the graylog side.
somewhere you have a problem.
If you send message with timestamp eg. 5pm, and you see the messages at 3pm with last 5 min settings, you won’t see the message from the future.