Build Correlation

(Tharaka) #1

I tried to build a correlation using log sources. As per my requirement I need to filter a source_ip address from one log source which has been blocked by IPS and I need to checked that blocked source_ip with another log source, source_ip whether matching attemps are there ?

source:server_a AND status:blocked AND srcip: (should match with) source:server_b AND scrip

Tried several possible logical condition. But unable to create it. Any idea on this are warmly welcome

(Jan Doberstein) #2

Maybe this plugin can help you - but with vanilla Graylog that is not possible.

(Tharaka) #3

How to I install given plugin in Graylog ?

(Jan Doberstein) #4

please read the documentation.

(system) closed #5

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.