Hi Team,
we are getting 300 devices log in our graylog server i.e Router,Switch,Firewall,Windows,. we want to filter or blocked some worst logs which we are getting on graylog from the source device. we didn’t require that log , so please help how I can block the some specific or repated log in graylog . please help to resolve the same
he @Shyambihari
you want to create some processing pipeline rules and the result is a drop of the message:
https://docs.graylog.org/en/4.0/pages/pipelines/functions.html#drop-message
Best place to stop the logs you don’t want is from the source. But if you can’t do that, what @jan mentioned would work also.
This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.