# Field content alert condition more than one value?

**URL:** <https://community.graylog.org/t/field-content-alert-condition-more-than-one-value/6208>\
**Category:** Graylog Central (peer support)\
**Tags:** pipeline-rules, sidecar, winlogbeat\
**Created:** [August 2, 2018, 9:56am UTC](https://community.graylog.org/t/field-content-alert-condition-more-than-one-value/6208 "2018-08-02T09:56:26Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![bestls](https://avatars.discourse-cdn.com/v4/letter/b/eb9ed0/32.png) [@bestls](https://community.graylog.org/u/bestls)\
**Post date:** [August 2, 2018, 9:56am UTC](https://community.graylog.org/t/field-content-alert-condition-more-than-one-value/6208/1 "2018-08-02T09:56:26Z")

</div>

Hello , everybody~  
i need to send a email alert when the field feedCode = 1 or feedCode = 3  
i know i can create more than one field content alert condition to resolve this issue.But Is there any good resolution to resolve this?Maybe use Regex or Logic character in graylog ？like OR？

---

<div class="post-metadata">

**Author:** ![pstatho](https://avatars.discourse-cdn.com/v4/letter/p/2bfe46/32.png) [@pstatho](https://community.graylog.org/u/pstatho)\
**Post date:** [August 6, 2018, 6:00pm UTC](https://community.graylog.org/t/field-content-alert-condition-more-than-one-value/6208/2 "2018-08-06T18:00:43Z")

</div>

I’m interested in this as well. In fact, I’m surprised we simply can’t use a Search query to trigger alerts. My use case is a I have a stream of logs I need to keep but I only want to alerts on certain conditions which requires AND or OR boolean logic of multiple fields.

---

<div class="post-metadata">

**Author:** ![jebucha](https://avatars.discourse-cdn.com/v4/letter/j/3be4f8/32.png) [@jebucha](https://community.graylog.org/u/jebucha)\
**Post date:** [August 6, 2018, 6:43pm UTC](https://community.graylog.org/t/field-content-alert-condition-more-than-one-value/6208/3 "2018-08-06T18:43:42Z")

</div>

Have you tried the Aggregates plugin from the marketplace?

> **[Graylog](https://marketplace.graylog.org/addons/0d01a899-138a-4f77-a9e7-04be4cc5e190)**
>
> Graylog

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [August 7, 2018, 1:42pm UTC](https://community.graylog.org/t/field-content-alert-condition-more-than-one-value/6208/4 "2018-08-07T13:42:03Z")

</div>

you could use a regex in the alert configuration for example.

---

<div class="post-metadata">

**Author:** ![pstatho](https://avatars.discourse-cdn.com/v4/letter/p/2bfe46/32.png) [@pstatho](https://community.graylog.org/u/pstatho)\
**Post date:** [August 20, 2018, 7:23pm UTC](https://community.graylog.org/t/field-content-alert-condition-more-than-one-value/6208/5 "2018-08-20T19:23:39Z")

</div>

I found a solution to my problem, since I don’t thing regex would have worked either. I’m using the Pipelines to look for specific conditions in my messages and then I set a new field such as alert:true. Then it’s a simple alert rule to alert when there is a field that with alert =true. So far it’s working as expected.

Here is my pipeline rule which can help others get on a similar path:  
rule “Interactive Login Failure”  
when  
has\_field(“winlogbeat\_keywords”) && contains(to\_string($message.winlogbeat\_keywords), “Audit Failure”) && has\_field(“winlogbeat\_event\_data\_LogonType”) && (to\_long($message.winlogbeat\_event\_data\_LogonType) == 2)  
then  
set\_field(“alert”, “true”);  
end

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [August 21, 2018, 8:42am UTC](https://community.graylog.org/t/field-content-alert-condition-more-than-one-value/6208/6 "2018-08-21T08:42:59Z")

</div>

Thank you for sharing @pstatho that is the best solution!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [September 4, 2018, 8:56am UTC](https://community.graylog.org/t/field-content-alert-condition-more-than-one-value/6208/7 "2018-09-04T08:56:32Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
