I’m attempting to write a very simple query.
I want to know when a disk is greater than 80% full. We have metricbeat reporting system.filesystem values and used_pct reports a disk used percentage per disk mount. Perfect.
However I can’t seem to query this used_pct number. It’s reported as a Float(long) but if I try to search for it using used_pct:>0.8
I get no results (we do have logs with values above 0.8). It appears that the search doesn’t understand anything but 0 and 1, it seems to be treating the used_pct value as an integer. I can do searches of >0 and <1 which return all logs. There’s nothing in the Graylog documentation or the Lucene documentation about specifically defining a number type in the query.
I don’t really want to write a pipeline for these as we get these logs every few seconds and it’ll add a lot of processing to something that should work with none.
What am I missing? (Graylog 3.3)