Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question. Don’t forget to select tags to help index your topic!
1. Describe your incident:
Hi everyone, I want to configure event definition so graylog would execute search only once and it should collect all logs and send to me in one notification. For example I wrote a pipeline which tells graylog to execute search after 6 o’clock everyday and at 9 in the morning it should stop the search. I want to configure Event Definition to execute search only once from 6 to 9 like summary and send me all logs that have been captured during this time. If it is possible please help. Thanks!
2. Describe your environment:
OS Information: Centos Linux 7
Package Version: 4.3.5
Service logs, configurations, and environment variables:
3. What steps have you already taken to try and solve the problem?
I have created the event notification and pipeline.
As for setting a specific time (i.e., 9PM) to send the alert I haven’t seen one, its basically dump it in a stream an set your search parameters/backlogs needed. Unless someone else here has done this.
With the Operation/Enterprise version you can.
Example:
Hi, gsmith for answer, could you please elaborate your pipeline section, as you can see in my pipeline there are two of them. In first stage I am setting out_of_work hours and in second stage I am implementing nonworkdays pipeline. However in your pipeline you wrote Route to stream rule. But I am not routing messages to the stream why you wrote this rule and could you please share this rule code.
Additionally, sometimes these pipeline rules is not working correctly and after rebooting the system, pipeline is starting to work. By the way thanks for sharing this valuable information with me it seems to me that reporting system is available only in enterprise mode.
The reason I have route_to_stream is for my event definition. while back I had some white noise so I decided to configured it this way. Soon as the logs hit this stream I can fine tune my Search within the last
Example: