Many thanks! index=* TERM(10.10.10.10) with host ip works, also need to expand the search time range (I use all in this case), found the syslog same date/time but different year though (in my case it's in 2017 or 2016 for two devices, same firmware/model ), going to dig in why it's been parsed like that.
... View more