Event Definitions Setup Help

  1. Describe your incident: Needing to create an event definition with an additional field for hostname
  2. Describe your environment:

Redhat 8
Graylog v4.3.5

  1. What steps have you already taken to try and solve the problem? I have setup a definition that works successfully, but when adding a custom field for Hostname, I get nothing.

I am using the following template

${source.hostname}

I am not sure if this is correct or not.

  1. How can the community help? Point in the proper direction for Event Definitions Template information.

Hey @monarch684

Not sure if thats a template, perhaps if you can share what you configured would help.

Does this help?

1 Like

Hey @monarch684

Thanks for the added info, What I did was the following for my Active directory.

Example:

This will show up Under alerts.

EDIT:
I also found this for ya, hopeit helps.

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.