I’ve encountered a really strange problem today and I’ve been bashing my head against a wall trying to resolve it all day.
I have a load of Field Content alert conditions configured and they were all working fine up until ~13:00 UTC
The MitreRef field is created and value assigned in a pipeline and is then routed into the stream which this alert condition is attached to.
I can see the messages in the system and the field/value has been assigned as expected however, the alert condition is still not triggering…
The time of the Graylog system and the Source system are the same. I have managed to get a Message Count Alert Condition to trigger successfully, it just appears to be the Field Content Alert Conditions that are failing for me.
- Graylog Version: 2.4.6+ceaa7e4
- Elasticsearch Version: 5.6.14
- MongoDB Version: 3.6.10
I have built a new box, imported everything I need. I can see that all my streams and pipelines are working as expected but, the same issue is persisting.
Has anyone got any ideas on this?