I tried to use the UI search box to quickly test the queries to use in the Icinga check that uses the API. I also use the Graylog REST API browser to figure out, what’s going on.
Doesn’t looks like they are separate to me as, for example:
{"sort_direction": "desc", "timerange": { "type": "relative", "from" : "864000"}, "query": "description:he \"time-server\"", "sort_by": "timestamp"}
Results in:
{
"events": [
{
"event": {
"id": "01JTXCXRGSFM2M3E25E3HMHC5C",
"event_definition_type": "aggregation-v1",
"event_definition_id": "66d5d3117cc5852aad4b50a1",
"origin_context": "urn:graylog:message:es:lfops-default_741:0f7ab020-2db3-11f0-985e-005056a1bf10",
"timestamp": "2025-05-10T15:25:52.052Z",
"timestamp_processing": "2025-05-10T15:27:22.649Z",
"timerange_start": null,
"timerange_end": null,
"streams": [
"000000000000000000000002"
],
"source_streams": [
"64804345385b9b5903fc2f82"
],
"message": "HE PDF 4 heights time-server error",
"source": "localhost",
"key_tuple": [],
"key": null,
"priority": 2,
"scores": {},
"associated_assets": [],
"alert": true,
"fields": {},
"group_by_fields": {},
"replay_info": {
"timerange_start": "2025-05-10T15:22:16.200Z",
"timerange_end": "2025-05-10T15:27:16.200Z",
"query": "source:icthepdf* AND message:\"response from time-stamp server\"",
"streams": [
"64804345385b9b5903fc2f82"
],
"filters": []
}
},
"index_name": "gl-events_25",
"index_type": "message"
},
{
"event": {
"id": "01JTXCXRGSB51MXGA34Z5KCEQT",
"event_definition_type": "aggregation-v1",
"event_definition_id": "66d5d3117cc5852aad4b50a1",
"origin_context": "urn:graylog:message:es:lfops-default_741:0f7ab021-2db3-11f0-985e-005056a1bf10",
"timestamp": "2025-05-10T15:25:52.052Z",
"timestamp_processing": "2025-05-10T15:27:22.649Z",
"timerange_start": null,
"timerange_end": null,
"streams": [
"000000000000000000000002"
],
"source_streams": [
"64804345385b9b5903fc2f82"
],
"message": "HE PDF 4 heights time-server error",
"source": "localhost",
"key_tuple": [],
"key": null,
"priority": 2,
"scores": {},
"associated_assets": [],
"alert": true,
"fields": {},
"group_by_fields": {},
"replay_info": {
"timerange_start": "2025-05-10T15:22:16.200Z",
"timerange_end": "2025-05-10T15:27:16.200Z",
"query": "source:icthepdf* AND message:\"response from time-stamp server\"",
"streams": [
"64804345385b9b5903fc2f82"
],
"filters": []
}
},
"index_name": "gl-events_25",
"index_type": "message"
},
{
"event": {
"id": "01JTXCXRGSBS4GQ9B09P1SCQG0",
"event_definition_type": "aggregation-v1",
"event_definition_id": "66d5d3117cc5852aad4b50a1",
"origin_context": "urn:graylog:message:es:lfops-default_741:ad07bf02-2db2-11f0-985e-005056a1bf10",
"timestamp": "2025-05-10T15:23:06.883Z",
"timestamp_processing": "2025-05-10T15:27:22.649Z",
"timerange_start": null,
"timerange_end": null,
"streams": [
"000000000000000000000002"
],
"source_streams": [
"64804345385b9b5903fc2f82"
],
"message": "HE PDF 4 heights time-server error",
"source": "localhost",
"key_tuple": [],
"key": null,
"priority": 2,
"scores": {},
"associated_assets": [],
"alert": true,
"fields": {},
"group_by_fields": {},
"replay_info": {
"timerange_start": "2025-05-10T15:22:16.200Z",
"timerange_end": "2025-05-10T15:27:16.200Z",
"query": "source:icthepdf* AND message:\"response from time-stamp server\"",
"streams": [
"64804345385b9b5903fc2f82"
],
"filters": []
}
},
"index_name": "gl-events_25",
"index_type": "message"
},
{
"event": {
"id": "01JTXCXRGS4DE4G87D995CMXTW",
"event_definition_type": "aggregation-v1",
"event_definition_id": "66d5d3117cc5852aad4b50a1",
"origin_context": "urn:graylog:message:es:lfops-default_741:ad07bf04-2db2-11f0-985e-005056a1bf10",
"timestamp": "2025-05-10T15:23:06.883Z",
"timestamp_processing": "2025-05-10T15:27:22.649Z",
"timerange_start": null,
"timerange_end": null,
"streams": [
"000000000000000000000002"
],
"source_streams": [
"64804345385b9b5903fc2f82"
],
"message": "HE PDF 4 heights time-server error",
"source": "localhost",
"key_tuple": [],
"key": null,
"priority": 2,
"scores": {},
"associated_assets": [],
"alert": true,
"fields": {},
"group_by_fields": {},
"replay_info": {
"timerange_start": "2025-05-10T15:22:16.200Z",
"timerange_end": "2025-05-10T15:27:16.200Z",
"query": "source:icthepdf* AND message:\"response from time-stamp server\"",
"streams": [
"64804345385b9b5903fc2f82"
],
"filters": []
}
},
"index_name": "gl-events_25",
"index_type": "message"
},
{
"event": {
"id": "01JTXCMK06XJQ0EPMR7B850WS4",
"event_definition_type": "aggregation-v1",
"event_definition_id": "66d5d3117cc5852aad4b50a1",
"origin_context": "urn:graylog:message:es:lfops-default_741:6d71d297-2db2-11f0-985e-005056a1bf10",
"timestamp": "2025-05-10T15:21:20.205Z",
"timestamp_processing": "2025-05-10T15:22:22.086Z",
"timerange_start": null,
"timerange_end": null,
"streams": [
"000000000000000000000002"
],
"source_streams": [
"64804345385b9b5903fc2f82"
],
"message": "HE PDF 4 heights time-server error",
"source": "localhost",
"key_tuple": [],
"key": null,
"priority": 2,
"scores": {},
"associated_assets": [],
"alert": true,
"fields": {},
"group_by_fields": {},
"replay_info": {
"timerange_start": "2025-05-10T15:17:16.200Z",
"timerange_end": "2025-05-10T15:22:16.200Z",
"query": "source:icthepdf* AND message:\"response from time-stamp server\"",
"streams": [
"64804345385b9b5903fc2f82"
],
"filters": []
}
},
"index_name": "gl-events_25",
"index_type": "message"
},
{
"event": {
"id": "01JTXCMK06K4QQRWK10M18XYGA",
"event_definition_type": "aggregation-v1",
"event_definition_id": "66d5d3117cc5852aad4b50a1",
"origin_context": "urn:graylog:message:es:lfops-default_741:6d71f9a0-2db2-11f0-985e-005056a1bf10",
"timestamp": "2025-05-10T15:21:20.205Z",
"timestamp_processing": "2025-05-10T15:22:22.086Z",
"timerange_start": null,
"timerange_end": null,
"streams": [
"000000000000000000000002"
],
"source_streams": [
"64804345385b9b5903fc2f82"
],
"message": "HE PDF 4 heights time-server error",
"source": "localhost",
"key_tuple": [],
"key": null,
"priority": 2,
"scores": {},
"associated_assets": [],
"alert": true,
"fields": {},
"group_by_fields": {},
"replay_info": {
"timerange_start": "2025-05-10T15:17:16.200Z",
"timerange_end": "2025-05-10T15:22:16.200Z",
"query": "source:icthepdf* AND message:\"response from time-stamp server\"",
"streams": [
"64804345385b9b5903fc2f82"
],
"filters": []
}
},
"index_name": "gl-events_25",
"index_type": "message"
}
],
"used_indices": [
"gl-events_25",
"gl-system-events_18"
],
"parameters": {
"page": 1,
"per_page": 10,
"timerange": {
"from": 864000,
"type": "relative"
},
"query": "description:he \"time-server\"",
"filter": {
"alerts": "include",
"event_definitions": [],
"priority": [],
"aggregation_timerange": null,
"key": [],
"id": [],
"extra_filters": {}
},
"sort_by": "timestamp",
"sort_direction": "desc",
"sort_unmapped_type": null
},
"total_events": 6,
"duration": 4,
"context": {
"event_definitions": {
"66d5d3117cc5852aad4b50a1": {
"id": "66d5d3117cc5852aad4b50a1",
"title": "HE PDF 4 heights time-server error",
"description": "PDF-Tools 4heights time-server not reached",
"remediation_steps": null
}
},
"streams": {
"000000000000000000000002": {
"id": "000000000000000000000002",
"title": "All events",
"description": "Stream containing all events created by Graylog",
"remediation_steps": null
}
}
}
}
And
{"sort_direction": "desc", "timerange": { "type": "relative", "from" : "864000"}, "query": "description:PDF", "sort_by": "timestamp"}
Results in:
{
"events": [],
"used_indices": [
"gl-events_25",
"gl-system-events_18"
],
"parameters": {
"page": 1,
"per_page": 10,
"timerange": {
"from": 864000,
"type": "relative"
},
"query": "description:PDF",
"filter": {
"alerts": "include",
"event_definitions": [],
"priority": [],
"aggregation_timerange": null,
"key": [],
"id": [],
"extra_filters": {}
},
"sort_by": "timestamp",
"sort_direction": "desc",
"sort_unmapped_type": null
},
"total_events": 0,
"duration": 2,
"context": {
"event_definitions": {},
"streams": {}
}
}
Which is consistent with the web view.