Hello Graylog Community,
we have tried hard to find something on this matter but mostly we found issues about this with “grok patterns”.
Searching extracted fields is no problem at all with normal regex expressions but we have a lot of trouble search the full_message and message entries. Most of the documentation is all about extracted fields and not the (full_)message entries. We need do search in message for strings like “john”:“doe” or entries like == or <= but as soon as we try to add the ",= or < Graylog either hangs or we don’t get any results. Escaping it with \ doesn’t help. Same outcome…
Any ideas how this works?
We are using Graylog 2.4.7 and Elastic 5.6.
Thank you very much and best regards,