Hello,
New to Graylog. Have recently installed Graylog (graylog-server-4.1.2-1, elasticsearch-7.10.2 on CentOS Linux release 7.9).
Trying to create my first aggregation for alerting purposes.
I have,
-
Set up Stream
-
Set up Pipeline using the stream
-
Added a rule to split log lines into fields using key_value()
-
Added a rule to convert selected fields into long using to_long()
-
-
When I try to create an aggregation in search, I receive the following error.
- When I check the type of the field I see that I have a combined type for the field ‘delayed’ which is both a string and a long.
Not sure where I should go from here. Suspect that I am missing something about elasticsearch types and indexes. If someone could point me in the right direction that would be great.
Regards,
Danny