Discussion:
[graylog2] Help creating fields (Streams, Pipelines and Rules)
d***@gmail.com
2016-12-23 19:59:01 UTC
Permalink
I've setup Snort integration with Graylog via
https://www.graylog.org/blog/64-visualize-and-correlate-ids-alerts-with-open-source-tools.
It's working quite well. now that I have a place to store remote logs I
thought I'd try and add those to Graylog too. I have syslog-ng listening
on my Graylog server and messages are rolling in from my remote servers.
I've created a stream, pipeline and stage to extract fields based on a
regex for a portion of the logs which deal with an IDS appliance. When I
click on the "Streams" menu item at the top of the Graylog UI, I can select
my IDS log stream and view the messages it's extracted. It seems to be
working correctly, except I don't see any of the fields I've set in my
Pipeline rule. It appears to be using the fields from the Snort integration
example (scr_addr, src_port, snort_alert, etc). What have I missed? Thanks.
--
You received this message because you are subscribed to the Google Groups "Graylog Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to graylog2+***@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/graylog2/32f520b9-3f62-4314-b11b-afcb2ee6a670%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
d***@gmail.com
2017-01-04 13:54:36 UTC
Permalink
I ended up putting all my custom Pipelines on the "Default stream" under
"System/Pipelines" to get it working. Just posting the followup in case it
helps anyone else.
--
You received this message because you are subscribed to the Google Groups "Graylog Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to graylog2+***@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/graylog2/95613659-caaf-4273-b13c-0eee237d1bad%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
i***@gmail.com
2017-02-16 17:59:13 UTC
Permalink
I am having the same problem with 2.2.0 release. If I set the Pipeline
connection to a specific Stream the Pipeline rule isn't applied (confirmed
the messages are going to the Stream). However, setting the Pipeline
connection to the default "All Messages" Stream seems to work fine. Am I
missing something?
Post by d***@gmail.com
I ended up putting all my custom Pipelines on the "Default stream" under
"System/Pipelines" to get it working. Just posting the followup in case it
helps anyone else.
--
You received this message because you are subscribed to the Google Groups "Graylog Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to graylog2+***@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/graylog2/c911c4a1-0b96-4a2d-adb9-13b0d2c90811%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
Continue reading on narkive:
Loading...