# Templates and Rules Exchange

**URL:** https://community.graylog.org/c/templates-and-rules-exchange/16.md

[Latest](https://community.graylog.org/latest.md) · [Categories](https://community.graylog.org/categories.md) · [Tags](https://community.graylog.org/tags.md)

---

## [About the Templates and Rules Exchange category](https://community.graylog.org/t/about-the-templates-and-rules-exchange-category/20662)

<div class="topic-metadata">

**Author:** [@dscryber](https://community.graylog.org/u/dscryber)\
**Replies:** 0\
**Last updated:** [July 28, 2021, 3:45pm UTC](https://community.graylog.org/t/about-the-templates-and-rules-exchange-category/20662 "2021-07-28T15:45:45Z")

</div>

Member suggested category just added: Got a template or rule to share with the Graylog Community? Here’s the place to post it. Got a request for a template or rule? Post it here where peers can share their knowledge …

---

## [Calix E7 OLT Syslog Pipeline Rule](https://community.graylog.org/t/calix-e7-olt-syslog-pipeline-rule/37046)

<div class="topic-metadata">

**Author:** [@WavedirectTel](https://community.graylog.org/u/WavedirectTel)\
**Replies:** 0\
**Last updated:** [March 3, 2026, 2:31pm UTC](https://community.graylog.org/t/calix-e7-olt-syslog-pipeline-rule/37046 "2026-03-03T14:31:30Z")

</div>

This will help strip a syslog from an E7 OLT to get the basics for troubleshooting ONT issues. rule "calix\_e7\_notfmgrd\_parse" when has\_field("message") && contains(to\_string($message.message), "notfmgrd\[") && cont…

---

## [Pipeline based decorator rules](https://community.graylog.org/t/pipeline-based-decorator-rules/37020)

<div class="topic-metadata">

**Author:** [@loggingone](https://community.graylog.org/u/loggingone)\
**Replies:** 0\
**Last updated:** [February 24, 2026, 11:58pm UTC](https://community.graylog.org/t/pipeline-based-decorator-rules/37020 "2026-02-24T23:58:39Z")

</div>

Have messages with extremely long lines. Figured out the pipeline rule code (for a decorator) that will correctly break the line down into appropriate components. Currently, can do “\\n” and can see that in the decorate…

---

## [Trying to use Pipelines to extract falues from a field](https://community.graylog.org/t/trying-to-use-pipelines-to-extract-falues-from-a-field/36715)

<div class="topic-metadata">

**Author:** [@dannymccaslin](https://community.graylog.org/u/dannymccaslin)\
**Replies:** 2\
**Last updated:** [December 12, 2025, 8:21pm UTC](https://community.graylog.org/t/trying-to-use-pipelines-to-extract-falues-from-a-field/36715 "2025-12-12T20:21:57Z")

</div>

I’m trying to extract some data from a particular field using Pipelines and while I think I understand it theoretically, I can’t seem to wrap my head around making it happen. We have a Palo Alto firewall with a VPN. We …

---

## [Grok works in test with sample data, unable to utilize in Pipeline rule](https://community.graylog.org/t/grok-works-in-test-with-sample-data-unable-to-utilize-in-pipeline-rule/36219)

<div class="topic-metadata">

**Author:** [@bralanak](https://community.graylog.org/u/bralanak)\
**Replies:** 1\
**Last updated:** [August 14, 2025, 9:26pm UTC](https://community.graylog.org/t/grok-works-in-test-with-sample-data-unable-to-utilize-in-pipeline-rule/36219 "2025-08-14T21:26:07Z")

</div>

Trying to wrap my head around this, not familiar with Graylog, but hoping to get it to work someday. I am utilizing NGINX Reverse Proxy Manager (NPM) on my network. I am successfully sending data to graylog. However, I g…

---

## [Sonicwall Pipeline Rules](https://community.graylog.org/t/sonicwall-pipeline-rules/27587)

<div class="topic-metadata">

**Author:** [@faen](https://community.graylog.org/u/faen)\
**Replies:** 19\
**Last updated:** [July 3, 2025, 7:28pm UTC](https://community.graylog.org/t/sonicwall-pipeline-rules/27587 "2025-07-03T19:28:32Z")

</div>

Sonicwall: TZ470 running SonicOS 7.01 Input type: Sylog/UDP Rule summary: Stage 0: Primary rule uses the “key\_value” function to parse the delimited message using the default delimiter of space. Stage 1: Four rules t…

---

## [Need to compress logs older than month to save space](https://community.graylog.org/t/need-to-compress-logs-older-than-month-to-save-space/34527)

<div class="topic-metadata">

**Author:** [@mohammad\_ramadan](https://community.graylog.org/u/mohammad_ramadan)\
**Replies:** 2\
**Last updated:** [December 27, 2024, 6:34am UTC](https://community.graylog.org/t/need-to-compress-logs-older-than-month-to-save-space/34527 "2024-12-27T06:34:08Z")

</div>

1. Describe your the incident: I have too many logs that are eating the storage space, I need a way to compress indecied to save storage OS Information: Ubuntu Linux v 22 (64-bit) Package Version: graylog 6.0.7

---

## [Rsyslog template](https://community.graylog.org/t/rsyslog-template/34021)

<div class="topic-metadata">

**Author:** [@brettjouw](https://community.graylog.org/u/brettjouw)\
**Replies:** 1\
**Last updated:** [November 6, 2024, 6:41pm UTC](https://community.graylog.org/t/rsyslog-template/34021 "2024-11-06T18:41:05Z")

</div>

Rsyslog Template Our environment has syslog collectors that use rsyslog to listen and write the events to disk in JSON format. The events are then picked up by Filebeats and shipped to Graylog. Just wanted to share my co…

---

## [IP to hostname lookup](https://community.graylog.org/t/ip-to-hostname-lookup/33927)

<div class="topic-metadata">

**Author:** [@dshirk](https://community.graylog.org/u/dshirk)\
**Replies:** 1\
**Last updated:** [October 24, 2024, 5:32pm UTC](https://community.graylog.org/t/ip-to-hostname-lookup/33927 "2024-10-24T17:32:52Z")

</div>

I do not have any templates yet. Here is the thing. I have found a resource here in the community how it explains how to show the DNS name to a device and not the IP. The problem is that the rule is in code format, and t…

---

## [Pipeline output printing in array instead of string](https://community.graylog.org/t/pipeline-output-printing-in-array-instead-of-string/33565)

<div class="topic-metadata">

**Author:** [@venki](https://community.graylog.org/u/venki)\
**Replies:** 2\
**Last updated:** [September 18, 2024, 1:31pm UTC](https://community.graylog.org/t/pipeline-output-printing-in-array-instead-of-string/33565 "2024-09-18T13:31:22Z")

</div>

I have the below pipeline processor rule that allows me to extract connectionId, ns and type from the mongodb log(json format), but unfortunately the extracted output is displaying as array instead of string. rule “Extr…

---

## [Convert base16 encoded key in readable text](https://community.graylog.org/t/convert-base16-encoded-key-in-readable-text/33248)

<div class="topic-metadata">

**Author:** [@ulo](https://community.graylog.org/u/ulo)\
**Replies:** 0\
**Last updated:** [August 13, 2024, 11:56am UTC](https://community.graylog.org/t/convert-base16-encoded-key-in-readable-text/33248 "2024-08-13T11:56:53Z")

</div>

Hello, i tried to convert base16 encoded key from an auditd messages into readable format with pipeline rules. for example: key=encoded\_string pipeline rule new\_key=decoded\_string I already discoverd the “base16\_dec…

---

## [Masking Sensitive Data on Graylog Pipeline Rules Script](https://community.graylog.org/t/masking-sensitive-data-on-graylog-pipeline-rules-script/33015)

<div class="topic-metadata">

**Author:** [@kctan](https://community.graylog.org/u/kctan)\
**Replies:** 1\
**Last updated:** [July 18, 2024, 3:45am UTC](https://community.graylog.org/t/masking-sensitive-data-on-graylog-pipeline-rules-script/33015 "2024-07-18T03:45:20Z")

</div>

Hello there Graylog Community, I want to mask the username but it does not work and only return the original message response. I have this Rule source: rule "mask\_sensitive\_fields" when has\_field("message") then le…

---

## [Tracking Print Jobs](https://community.graylog.org/t/tracking-print-jobs/23138)

<div class="topic-metadata">

**Author:** [@tmacgbay](https://community.graylog.org/u/tmacgbay)\
**Replies:** 2\
**Last updated:** [April 26, 2024, 4:36pm UTC](https://community.graylog.org/t/tracking-print-jobs/23138 "2024-04-26T16:36:44Z")

</div>

While tooling around on the internets I came across some logging information on Windows Print jobs. Our current setup shoots all of the company print jobs through a couple of Windows print servers and it turns out it i…

---

## [Json nested and lsit](https://community.graylog.org/t/json-nested-and-lsit/30637)

<div class="topic-metadata">

**Author:** [@flep](https://community.graylog.org/u/flep)\
**Replies:** 9\
**Last updated:** [April 15, 2024, 10:42pm UTC](https://community.graylog.org/t/json-nested-and-lsit/30637 "2024-04-15T22:42:25Z")

</div>

Hello, I try to format my json log, but so far without success. My goal is to be able to parse the nested field like : httpRequest, ruleListGroup My current setup is quite easy, I defined a JSON extractor for an raw-…

---

## [Problems with greynoise pipeline](https://community.graylog.org/t/problems-with-greynoise-pipeline/31958)

<div class="topic-metadata">

**Author:** [@martinhoCMA](https://community.graylog.org/u/martinhoCMA)\
**Replies:** 2\
**Last updated:** [March 27, 2024, 3:11pm UTC](https://community.graylog.org/t/problems-with-greynoise-pipeline/31958 "2024-03-27T15:11:29Z")

</div>

Hey everyone, I’ve been trying to put to work a pipeline that integrates my fortigate logs (that come to graylog via syslog) with Greynoise, but unfortunetly it’s not working. It does not make any enrichment to my data. …

---

## [Struggling to use parse\_json()](https://community.graylog.org/t/struggling-to-use-parse-json/31905)

<div class="topic-metadata">

**Author:** [@mgfranky](https://community.graylog.org/u/mgfranky)\
**Replies:** 1\
**Last updated:** [March 25, 2024, 7:34am UTC](https://community.graylog.org/t/struggling-to-use-parse-json/31905 "2024-03-25T07:34:23Z")

</div>

Hi, I’m using Graylog 5.2.5. I’m trying to parse a simple Json string. I’m using the “Source Code Editor” Here is my Rule Source: rule “test” when has\_field(“message”) then let json = parse\_json(to\_string($message…

---

## [Strange problem with pipeline](https://community.graylog.org/t/strange-problem-with-pipeline/31689)

<div class="topic-metadata">

**Author:** [@Demiurg](https://community.graylog.org/u/Demiurg)\
**Replies:** 2\
**Last updated:** [March 11, 2024, 2:29pm UTC](https://community.graylog.org/t/strange-problem-with-pipeline/31689 "2024-03-11T14:29:15Z")

</div>

Hi. My Graylog server (5.2.4) routes logs from sidecar (audibeat) to two streams - streams A and B (by streams rules) and its ok. Stream A should keep oryginal log but stream B should keep only few fields. So I create…

---

## [Try to remove brackets from string](https://community.graylog.org/t/try-to-remove-brackets-from-string/30722)

<div class="topic-metadata">

**Author:** [@Chris\_1](https://community.graylog.org/u/Chris_1)\
**Replies:** 5\
**Last updated:** [November 21, 2023, 10:16pm UTC](https://community.graylog.org/t/try-to-remove-brackets-from-string/30722 "2023-11-21T22:16:15Z")

</div>

Hello, from the example string below, im trying tor replace the brackets and the number between these bracktes with a dot (.). I used a pipline rule for this. example String: “(10)nexusrules(10)officeapps(4)live(3)com(…

---

## [How to test field value using regex? in favor to determ if extractor has to run](https://community.graylog.org/t/how-to-test-field-value-using-regex-in-favor-to-determ-if-extractor-has-to-run/30738)

<div class="topic-metadata">

**Author:** [@louis](https://community.graylog.org/u/louis)\
**Replies:** 1\
**Last updated:** [November 20, 2023, 1:41pm UTC](https://community.graylog.org/t/how-to-test-field-value-using-regex-in-favor-to-determ-if-extractor-has-to-run/30738 "2023-11-20T13:41:00Z")

</div>

I am building extractors to parse an alarmlog with comma separated fields. Depending on field values I need to use a a different extractor. So I use the only execute extractor if regex is true field. However that is ea…

---

## [Preliminary storage architecture for logging data](https://community.graylog.org/t/preliminary-storage-architecture-for-logging-data/30435)

<div class="topic-metadata">

**Author:** [@Marvin1](https://community.graylog.org/u/Marvin1)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 3:51pm UTC](https://community.graylog.org/t/preliminary-storage-architecture-for-logging-data/30435 "2023-10-24T15:51:55Z")

</div>

Preface: Efficient storage and management of log data is a vexed topic, mainly due to the mass of data and its size. Nevertheless, it has a crucial importance for our business. In this blog post, I will present a prelimi…

---

## [Incorrectly parsed fileds](https://community.graylog.org/t/incorrectly-parsed-fileds/30257)

<div class="topic-metadata">

**Author:** [@dandu](https://community.graylog.org/u/dandu)\
**Replies:** 1\
**Last updated:** [October 6, 2023, 4:17am UTC](https://community.graylog.org/t/incorrectly-parsed-fileds/30257 "2023-10-06T04:17:17Z")

</div>

What options do I have when Graylog parses message fields incorectly? For example here’s a message from a FortiGate firewall: date=2023-10-05 time=10:32:59 devname=“hostname” logid=“0317013312” type=“utm” subtype=“webf…

---

## [Setup a pipeline rules for certain hours 5.1.4](https://community.graylog.org/t/setup-a-pipeline-rules-for-certain-hours-5-1-4/30080)

<div class="topic-metadata">

**Author:** [@aliraxa](https://community.graylog.org/u/aliraxa)\
**Replies:** 6\
**Last updated:** [September 14, 2023, 7:53am UTC](https://community.graylog.org/t/setup-a-pipeline-rules-for-certain-hours-5-1-4/30080 "2023-09-14T07:53:14Z")

</div>

Hi, @gsmith I have created a rule in pipeline for certain hours means when (off hours), I have share the rule as well but it didn’t work for me. My graylog version is 5.1.4 rule “Between 6 PM and 6 AM” when ( to\_long…

---

## [Graylog, sidecar, and nginx](https://community.graylog.org/t/graylog-sidecar-and-nginx/30015)

<div class="topic-metadata">

**Author:** [@TekieG](https://community.graylog.org/u/TekieG)\
**Replies:** 1\
**Last updated:** [September 7, 2023, 7:55pm UTC](https://community.graylog.org/t/graylog-sidecar-and-nginx/30015 "2023-09-07T19:55:54Z")

</div>

I have nginx as reverse proxy and GrayLog on separate networks and servers. Nginx is the only server exposed to the outside. nginx and graylog do communicate properly and I can access the API externally no problem. My si…

---

## [Graylog Extractor by Regular Expression](https://community.graylog.org/t/graylog-extractor-by-regular-expression/29955)

<div class="topic-metadata">

**Author:** [@davidfungf](https://community.graylog.org/u/davidfungf)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 2:12pm UTC](https://community.graylog.org/t/graylog-extractor-by-regular-expression/29955 "2023-09-05T14:12:16Z")

</div>

How do I extract the json data {…} and eliminate the “created live/iot” by Graylog regular expression? Thanks. created live/iot {"consumerGroup":"iot-gtwinsg","eventBody":{"iotData":\[{"id":{"reading":"293790536467218432…

---

## [Trying to configure a json extractor but get nothing to extract message](https://community.graylog.org/t/trying-to-configure-a-json-extractor-but-get-nothing-to-extract-message/29214)

<div class="topic-metadata">

**Author:** [@thomasevig](https://community.graylog.org/u/thomasevig)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 3:11am UTC](https://community.graylog.org/t/trying-to-configure-a-json-extractor-but-get-nothing-to-extract-message/29214 "2023-06-20T03:11:20Z")

</div>

Hello, i am new around here hopefully i’ll manage to get some answers!! :stuck\_out\_tongue: so, we have a syslog input that receives messages, im trying to parse them to have new fields by using extractors. i am using…

---

## [Problem understanding the use of is\_json function](https://community.graylog.org/t/problem-understanding-the-use-of-is-json-function/28817)

<div class="topic-metadata">

**Author:** [@hasturo](https://community.graylog.org/u/hasturo)\
**Replies:** 5\
**Last updated:** [June 1, 2023, 9:18pm UTC](https://community.graylog.org/t/problem-understanding-the-use-of-is-json-function/28817 "2023-06-01T21:18:33Z")

</div>

Hi Guys, im trying to understand if can utilize “is\_json” for differ between Json and not Json Content in Message field in Pipeline Rules. From my understanding i could use something like this: rule “Test for JSON” w…

---

## [Add a comma between fileds in pipeline rule](https://community.graylog.org/t/add-a-comma-between-fileds-in-pipeline-rule/28325)

<div class="topic-metadata">

**Author:** [@mk1762](https://community.graylog.org/u/mk1762)\
**Replies:** 2\
**Last updated:** [April 3, 2023, 11:57am UTC](https://community.graylog.org/t/add-a-comma-between-fileds-in-pipeline-rule/28325 "2023-04-03T11:57:33Z")

</div>

Hi, I have this simple rule, I would to add a comma between these two fields (cs7\_latitude and cs8\_longitude) but it doesn’t work, there’s an escape char to use or other methods ? rule “GPS” when has\_field(“cs7\_latit…

---

## [Graylog ingesting Crowdstrike FDR Logs (refined repost)](https://community.graylog.org/t/graylog-ingesting-crowdstrike-fdr-logs-refined-repost/27725)

<div class="topic-metadata">

**Author:** [@enjet\_it](https://community.graylog.org/u/enjet_it)\
**Replies:** 3\
**Last updated:** [February 16, 2023, 6:02pm UTC](https://community.graylog.org/t/graylog-ingesting-crowdstrike-fdr-logs-refined-repost/27725 "2023-02-16T18:02:03Z")

</div>

I spent days searching for a solution to the above. Graylog’s AWS plugin doesn’t work in this case unless you have your own bucket that FDR is dumping into, and Filebeat can’t read the input (likely because the data is s…

---

## [Anonymize IPv4 address](https://community.graylog.org/t/anonymize-ipv4-address/20685)

<div class="topic-metadata">

**Author:** [@shoothub](https://community.graylog.org/u/shoothub)\
**Replies:** 3\
**Last updated:** [January 28, 2023, 12:55am UTC](https://community.graylog.org/t/anonymize-ipv4-address/20685 "2023-01-28T00:55:11Z")

</div>

Sometimes you need to anonymize IPv4 address. There are lot of solutions, one simple is to replace last octet with some text. This little snippet uses this approach to replace all ipv4 address in message: rule "Anonymiz…

---

## [Vcenter/ESxi Log Source - Build pineline rule to detect attack based on blacklist URL](https://community.graylog.org/t/vcenter-esxi-log-source-build-pineline-rule-to-detect-attack-based-on-blacklist-url/27272)

<div class="topic-metadata">

**Author:** [@taibui](https://community.graylog.org/u/taibui)\
**Replies:** 0\
**Last updated:** [January 13, 2023, 10:07am UTC](https://community.graylog.org/t/vcenter-esxi-log-source-build-pineline-rule-to-detect-attack-based-on-blacklist-url/27272 "2023-01-13T10:07:37Z")

</div>

We collect all blacklist URL which can use to attack vcenter/esxi server from remote address. If we push logs to a centralized system like Graylog, we can immediately detect attacks on the system. Link github: Team S…

[Next page](https://community.graylog.org/c/templates-and-rules-exchange/16.md?page=1)
