I’m starting in Graylog and I want tell that is great this tools. I’m trying do some things like execute rule but in order but I can’t do It.
So I want create this rule for example:
- One Stream for fails logon events
- One Stream for succes logon eventos
This idea is for:
- Aggrupation for same user
- Theses rule must execute in order, firts the one Stream and second Stream then.
- Alert if this condition is ok
I don’t see the way do It, sorry but I’m new in Graylog.