Event Correlation

I have an important use case involving event correlation and I’m wondering if Graylog can do it…

I need to track when a bgp neighbor goes down (and do a dns lookup on the address of the peer to report it as the location) and then when that same neighbor comes back up, compute the time it was down and report the location and the time it was down.

From what I read it seems like it was not possible in previous versions but it might be in the latest version. Can someone tell for for certain?


that is not possible in the current version - but 3.1 will have something.

The planned release is august this year.

