Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Display Filter Reference: Graylog Extended Log Format

Protocol field name: gelf

Versions: 3.2.0 to 4.2.4

Back to Display Filter Reference

Field name Description Type Versions
gelf.broken_compressionCan't unpack messageLabel3.2.0 to 4.2.4
gelf.chunk.countChunk countUnsigned integer (8 bits)3.2.0 to 4.2.4
gelf.chunk.msg_idMessage idByte sequence3.2.0 to 4.2.4
gelf.chunk.numberChunk numberUnsigned integer (8 bits)3.2.0 to 4.2.4
gelf.chunkedChunked messageBoolean3.2.0 to 4.2.4
gelf.fragmentGELF fragmentFrame number3.2.0 to 4.2.4
gelf.fragment.countGELF fragment countUnsigned integer (32 bits)3.2.0 to 4.2.4
gelf.fragment.errorGELF defragmentation errorFrame number3.2.0 to 4.2.4
gelf.fragment.multiple_tailsGELF has multiple tail fragmentsBoolean3.2.0 to 4.2.4
gelf.fragment.overlapGELF fragment overlapBoolean3.2.0 to 4.2.4
gelf.fragment.overlap.conflictsGELF fragment overlapping with conflicting dataBoolean3.2.0 to 4.2.4
gelf.fragment.too_long_fragmentGELF fragment too longBoolean3.2.0 to 4.2.4
gelf.fragmentsGELF fragmentsLabel3.2.0 to 4.2.4
gelf.invalid_headerInvalid headerLabel3.2.0 to 4.2.4
gelf.reassembled.inReassembled GELF in frameFrame number3.2.0 to 4.2.4
gelf.reassembled.lengthReassembled GELF lengthUnsigned integer (32 bits)3.2.0 to 4.2.4
gelf.typeGELF TypeUnsigned integer (16 bits)3.2.0 to 4.2.4