Trying to get this module to work with Graylog indexes without any success... Could it be because Graylog creates indexes differently with @timestamp or timestamp? When I try the same query manually with Insomnia it works.
Current Behavior
I am getting an error 400
Possible Solution
None
Steps to Reproduce (for bugs)
My config files:
instances.ini
[esearch1.lab.local]
uri = "http://esearch1.lab.local:9200"
user = ""
password = ""
ca = ""
client_certificate = ""
client_private_key = ""
Expected Behavior
Trying to get this module to work with Graylog indexes without any success... Could it be because Graylog creates indexes differently with @timestamp or timestamp? When I try the same query manually with Insomnia it works.
Current Behavior
I am getting an error 400
Possible Solution
None
Steps to Reproduce (for bugs)
My config files:
instances.ini
eventtypes.ini
Context
Example of what I see in a packet capture:
Your Environment
icinga2 --version
): 2.9.1curl http://localhost:9200
): 5.6.11