New to Graylog. Have recently installed Graylog (graylog-server-4.1.2-1, elasticsearch-7.10.2 on CentOS Linux release 7.9).
Trying to create my first aggregation for alerting purposes.
Set up Stream
Set up Pipeline using the stream
Added a rule to split log lines into fields using key_value()
Added a rule to convert selected fields into long using to_long()
When I try to create an aggregation in search, I receive the following error.
- When I check the type of the field I see that I have a combined type for the field ‘delayed’ which is both a string and a long.
Not sure where I should go from here. Suspect that I am missing something about elasticsearch types and indexes. If someone could point me in the right direction that would be great.