I understand that this will probably involve using the predefined pipeline functions, or creating a new one. What I’m not clear on at this point is specifically where to place the information and how to generate what I need to compare timestamps in log messages.
My specific problem: I want to create a stream for all log messages which occur between 21:00:00UTC and 13:00:00UTC during a given day. From there, I will create alerts based on the value of e.g. the EventType field.
Do I need to generate a current date, then replace the hours with those I need to compare?
Can I create a date that matches all years/months/days with a wildcard?
Is there a way to say in graylog/elasticsearch ‘between these dates’?