For some rule types (like Group/Distinct, AND, THEN, OR) you can choose one or multiple fields for the Group by Condition.
When you begin to type the name of the field, a list of existing fields is shown.
However it's case insensitive. It should be case sensitive because field names are case sensitive.
Issue:
- You want to group by field "user"
- This field is not known by Graylog (no log with this field has been received yet)
- Graylog only knows the field "User" (with a uppercase "U")
- If you type "user" in the group by condition, it only shows "User" and you can't choose Create "xxx" (as you can when the field is unknown)