I am trying to drop some messages before they go into the “all messages” stream and therefore get indexed. I have a single input (syslog udp) and some extractors on it.
I’m new to graylog and could not figure out how to do this - the pipeline and rule I created are working but can only be applied to streams (but not to “all messages”), at which point the message I would like to drop is already routed into “all messages” as well.
Processors order is Message Filter Chain then pipelines.
What am I misunderstanding here?
Thanks in advance