Hi, I’m running a fresh install of graylog 2.3.1. I currently have logs pouring in from my AD servers. I installed nxlog but could not get sidecar to work. Regardless, nxlog is working and I do see messages pouring in so I think I have it setup correctly.
I seem to be having trouble getting queries to work properly on the main screen. My goal is to query AD events like account lockouts and such and see daily counts on my dashboard widgets. I’m using the Active Directory Auditing module for some of the built in widgets and streams to accomplish this. However, they don’t seem to be accurate or even working sometimes. Every time I try to query for something like “EventId: 4740” I get “nothing found” even though I know I can see the logs on the main page. I thought it could have something to do with the colon so I tried escape characters like EventID: 4740 but that just returned more irrelevant results. The built in stock counters in the module are displaying incorrect information (or not working) so I think these issues are related.
Any help would be greatly appreciated!