Hi all.
We tried to make event definition and wrote this points:
in Filter&Aggregation>Aggregation used 3 fields (src_address, dst_address, protocol)
making Fields src_address, dst_address, protocol
and it does no alerts at all…
when we leave only 1 field - it works
more then 1 -no alert and no fields
when we leave 1 field and 3 fields - we get 1 alert and 1 field in notifications
who can help or explain how it works?
I’m not sure what version of Graylog your using, also its hard to tell what could be the problem. Could you explain what your goal is with Filter&Aggregation in greater detail? Maybe some examples of the outcome you wanted and/or messages your trying to filter out. That would be very helpfull.
I add new custom field with name dst_address, it doesn’t work
i make a template for custom field like ${source.dst_address} and destination addresses contains in basic event, but in alert we get an empty field, how it works? why value of the field doesnt extract to alert?
This could be a combination of different things. Maybe the field does not have data in it, or how the messages are processed. Unfortunately, with the lack of information like how you created those fields its hard to say.
Showing how you did configurations would helps us to help you troubleshoot your issue.
these fields work and added to notification in alerts, when i want to add protocol name or dst_port number with template ${source.nf_proto} - no info adds to alert
I’m not to familiar with Event fields section. I just never had to use it yet.
How ever I did find These , maybe something in there might help.
As for creating custum fields you probably can do this on the INPUT by creating a GROK or Regular expression. Then use those fields to filter out what you need. I’m sorry I cant be more help.
@aldot
Hello,
So I did some testing on Netflow INPUT UDP. I was using the default configuration and found a lot of fields that get generated. These also have fields for destination address (dst_address). Not sure why you would want to create another field for the same thing. Maybe try using the default fields instead to see if you get better results.
Here is the list of fileds that I have found.