GrayLog 6 - Source Alert

Hello everyone,

My setup - graylog 6.0.3
I have a firewall stream and in this stream 10 firewalls send the logs
Now I would like to know, when a firewall no longer send logs?

I would like to receive an alarm message - SMS or notification

How can I best implement this?
Suggestions?

Thanks!

Thanks, but how can I trigger an alert from an event?

thx

https://go2docs.graylog.org/current/interacting_with_your_log_data/alerts.html

The links provided by @patrickmann will help you to create an alert if the Stream has no log, which means all firewall stopped to send logs.
Unfortunately as far as I know it isn’t possible to create a rule to be alerted if only one firewall stop to send logs (or you need to create a specific rule for each firewall but it’s really not handy)

Can anyone tell me what is meant by GrayLog Cluster Alert ?

thx

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.