I’m trying to setup streams at my graylog node. I’m able to successfully create a stream and enable rules. After enabling those rules i do not recieve any syslog messages on those streams.
I can confirm that my inputs do recieve messages, and the standard ‘All messages’ stream does also. one thing i noticed is that the elasticearch query uses a different timestamp.
Time configuration
User admin:
** 2017-12-14 12:38:32 +01:00** Your web browser:
** 2017-12-14 12:38:32 +01:00** Graylog server:
** 2017-12-14 12:38:32 +01:00**
And below the elasticsearch query using the ‘last 5 min’:
Did you confirm that the “Message Processors Configuration” matches between the 2 servers? If you go to system>configuration there is a control for the order in which messages are processed. I banged my head against the wall for a few hours one day before realizing that my message filter was processing after my piplines.