Searching for multiple terms

Relative Graylog newbie here. I am scratching my head here because nothing I try here seems to yield the expected results.

In our logs is a Message field that contains the complete text of our ASA log entry.

I am trying to search in that field only, for multiple terms… like a syslog code and a username but nothing I try works.

Example: %ASA-4-113019 AND jsmith

This doesn’t work. Is my syntax wrong or can this type of search not be done?

Thanks.

John

Did you try putting the phrases in quotes? i.e. “%ASA-4-113019” AND ”jsmith”?

1 Like

did you checked the docs on that?

http://docs.graylog.org/en/3.0/pages/queries.html

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.