Search for number with timestamp in message

Hi there

I’m trying to search trough my logs for the number 53.
my messages look like this:
Mar 12 2021 14:12:53: %6-302016: Teardown UDP connection 863583 for xxxxxxxx/58255 to 8.8.8.8/53 duration 0:00:00 bytes 0

My current search string is similar to this:
“1.6.1.1” OR “10.6.3.2” AND NOT “208.67.222.222” AND NOT “208.67.220.220” AND “/53”

The problem is that when i search for “/53”, for some reason the “/” is ignored, and a ton of results that have 53 in the timestamp in the beginning of the message is found.

Any ideas on how I cant prevent this?

Does this help?
image
From Search query language — Graylog 4.0.0 documentation

1 Like

Thanks, but unfortunately not. It’s still like the “/” is ignored :confused:

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.