Stream rules not working

ive set up wazuh sending logs to graylog succesfully, created streams and indices that are working but for some reason specific logs are missing from in my fortigate stream but are in my archives stream, ive set the stream rules but it isnt working. even specifically matching all rules it still doesnt work please advise.

i even loaded a message to test the rules and it does show all green and that the message will be routed into this stream but it is still empty

Can you share an example of a log message that is failing to show up, along with the pipeline rule?
I assume you already checked the Failure Stream for any issues in processing.
The first thing to look for is always a timezone mismatch. But we’d need some more details to see what is going on.

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.