Hi @Santosh2, maybe the timestamp isn't correctly parsed, try to search something special of your logs in a very large time period. Then, if you're searching logs in the first 11 days of the month, try to search the 1st of may (01/05/2022) at the 5th of january (05/01/2022). Then, are you sure about index? then, try to add an asterisk at the beginning of the source, maybe there's the full path and/ot an asterisk at the end of host, maybe there's the FQDN name instead of the hostname. Ciao. Giuseppe
... View more