Hi --I am not sure how to diagnose this issue. My searching has offered no results.
When I try to refine my iptables query with > log.original: "ID=1234" I get the error:
failed to create query: Cannot search on field [log.original] since it is not indexed.
I am surprised to find this error because the log.original field has the 't' icon which I understood meant it is indexed. Either way, can you please help me determine if this is or is not indexed, and if not, how can I achieve that?
Thanks. I did this in dev tools GET /filebeat-*/? and got 29, 138 lines! I am unable to find anything with log.original specifically. What should I be looking for?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.