Hello,
I have 10 servers sending their syslog and auditd information to a centralized Nagios Log Server. I'd like to find the documents that contain "type=EXECVE". However, if I do that (and there are PLENTY of documents with that string plastered all over, nothing shows up after performing that query. I can do "type" or "type=", but then only "type" is highlighted, making the search useless for me.
What am I doing wrong?
Thanks,
Daniel
Query/Search Issues
Re: Query/Search Issues
Give this query a try:
Code: Select all
type:EXECVERe: Query/Search Issues
jolson wrote:Give this query a try:
Code: Select all
type:EXECVE
This does not work. However, I have just been using "EXECVE" and that has been working for me. But why can I not query more than one word? For example, "this = myQuery" only results in the word "this" being highlighted...
Thanks for your help.
Re: Query/Search Issues
Can you possibly show us a screenshot of one of the logs, expanded out. I want to see what fields it is generating.
Former Nagios Employee.
me.
me.