Ok I’m not quit getting what you want but I did get more information about your environment. I need to ask a couple question to get a better understanding on what’s going wrong or what you want to do.
Let’s sum it up and see if I’m correct
- You have all the fields created through some package you installed?
- You can see these fields in the messages received?
- The fields that were create by some package you installed don’t work on your widgets?
- I think you want to create a widget for the field fw_fwrule?
- The value/data of the field fw_fwrule changes every week?
Could you explain the statement above? Are you referring that you can not make a midget from those fields?
When you stated specific rule are you referring to Stream rules?
There is different kinds of rule/s in Graylog specially Streams but if were focusing on Widgets could you show a screenshot of what rule/s are you referring to? or are you referring to fields in that statement?
Screenshot would work really good explaining what you want or trying to do. The screenshot above e doesn’t really tell me much, only that those configuration work for that aggregation widget.
If the field fw_fwrule is always present in the log message and the data changes weekly, that seems normal. Since the Timestamp field data changes every second.
And last, can you explain this statement below, I’m not sure what you mean.
Perhaps showing an example of what your trying to do. I seen your statement that your limited on screenshots.
Maybe try these steps and show what happens. Focusing on the FIELD fw_fwrule .
BTW this is version 4.2 BUT you can adapt it to your version.
Navigate to the the upper left corner of the Web UI and click on “Search”.
On the Left pane click on the “+” sign then click on the Aggregation button shown below.
Now you should see this.
Click on edit button. There should be “+” signs shown. Click on those to see all your options.
Go to Group By section and click the down arrow, there should be all your fields that were created.
There you should be able to choose the field fw_fwrule.
Here is my example hope that helps.