Searching for multiple terms

(John Rumball) #1

Relative Graylog newbie here. I am scratching my head here because nothing I try here seems to yield the expected results.

In our logs is a Message field that contains the complete text of our ASA log entry.

I am trying to search in that field only, for multiple terms… like a syslog code and a username but nothing I try works.

Example: %ASA-4-113019 AND jsmith

This doesn’t work. Is my syntax wrong or can this type of search not be done?

Thanks.

John

(Megan) #2

Did you try putting the phrases in quotes? i.e. “%ASA-4-113019” AND ”jsmith”?

1 Like
(Jan Doberstein) #3

did you checked the docs on that?

http://docs.graylog.org/en/3.0/pages/queries.html