Hi All,
Is it possible to set alerts on trends? This post gives a nice example on trend analysis TREND ANALYSIS WITH GRAYLOG but with no hints on how to setup alerts on, say, sudden spike in incoming messages.
I initially thought that maybe the enterprise correlation engine would be required for that, but having watched https://www.graylog.org/videos/correlation-engin I’m not sure, seems the correlation thresholds are also just numbers, not relative values.
So… any recommended / feasible way on setting alerts when trends change?
Regards,
Mike
ps. I’m on Graylog 3.2.4+a407287 (AdoptOpenJDK 11.0.6 on Linux 5.3.0-40-generic) / Ubuntu 18.04.4 LTS; filebeat is the main source of data into Graylog.