Quick Values for message

(Ayoub) #1

hi everyone,
Please I want to know how i get " Quick Values for message" in Serach result.
I want a clear answer
message

0 Likes

(Jan Doberstein) #2

Graylog UI System > configuration

1 Like

(Ayoub) #3

0 Likes

(Jan Doberstein) #4

it is allowed to think!

1 Like

(Ayoub) #5

please how to make it enable

0 Likes

(Jan Doberstein) #6

click on “update” - scroll down and change/remove the fields that are disabled for analysis.

As I said, you are allowed to think.

0 Likes

(Ayoub) #7

i did it , same problem

0 Likes

(Ayoub) #8

remove all of theme or just one in front of ui analysis ( P30D…) ??

0 Likes

(Ayoub) #10

Hey Everybody,
Please i would generate " Quick Values for message " graph

0 Likes

(Jan Doberstein) #11

this is disabled for a reason by default …

… check your elasticsearch log, you might notice some Out-of-Memory error or something similar.

The error is a 500, so the backend (elasticsearch) returns an error on that field.

Again check your elasticsearch log.

1 Like

(Ayoub) #12


Hi @jan please explain to me i would have a quick values message graph ! how !!! i can’t fix this erreur !!

0 Likes

(Jan Doberstein) #13

it is not possible.

The field messages holds a wide range of information, this field is analyzed and if you make it unique and count those it will break. That is the reason for the 500 …

You might want to normalize your logs, seperate the information that are in the message field into multiple different fields. Please read the community, You should fokus on reaching the goal, but not bending something into the position you like to have it.

1 Like

(Ayoub) #14

Hi @jan please I Want to Know Why when i spear systemctl status graylo-server.service … the service graylog " flops "…I searched for a lot…it’s weird; I hope you understand me

0 Likes

(Ayoub) #15

journalctl -xe

0 Likes

(system) closed #16

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.

0 Likes