I’m starting in Graylog and I want tell that is great this tools. I’m trying do some things like execute rule but in order but I can’t do It.
So I want create this rule for example:
One Stream for fails logon events
One Stream for succes logon eventos
This idea is for:
Aggrupation for same user
Theses rule must execute in order, firts the one Stream and second Stream then.
Alert if this condition is ok
I don’t see the way do It, sorry but I’m new in Graylog.