Relative Graylog newbie here. I am scratching my head here because nothing I try here seems to yield the expected results.
In our logs is a Message field that contains the complete text of our ASA log entry.
I am trying to search in that field only, for multiple terms… like a syslog code and a username but nothing I try works.
Example: %ASA-4-113019 AND jsmith
This doesn’t work. Is my syntax wrong or can this type of search not be done?
Thanks.
John