Hi everyone I have some difficulties with searching messages within the streams.
In my case I have connected Domain Controller to my Graylog server so via winlogbeat I am getting messages to streams in graylog.
I want to search Account name which includes letters PC.
In logs we have lots of names which include letters PC so when I am searching exact expression like in this photo(201PC3302) search query give results for exact matching but I want to search every message with letters PC.
My Search Query is ( beats_type:winlogbeat AND message:" Logon Type: 3 " AND message:"Account Name: PC ")
This query is not giving any results.
Looks like there is a quotes issue here. If you are typing/copying/pasting directly into the forums you get quotes like these “” but Graylog (Elasticsearch and Mongo) all choke on those. Make sure you are using " quotes in all instances where you are creating queries or writing pipeline rules…
I found how to do it thanks for helping me.
beats_type:winlogbeat AND message:" Logon Type: 3 " AND message:“Account Name” AND message: PC
By searching like that you could find all messages which includes Letters PC. Logon Type 3 field is the Domain controller message type you could remove it if you want when searching. " quotes is not working unfortunately.