New stream search shows only the last 5 minutes of data


I have set the firewall log to be visible on the graylog.
To manage only firewall log data separately, we created a separate firewall log index and a separate stream.

I found a problem here, and the firewall logs from All Messages look as much as the data received, but only the last five minutes of data from Firewall Log Stream.

I don’t know if this only stores five minutes of data or only five minutes of data in a search.

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.