Graylog Alerting Question

(smigal) #1

Hello community !

I want to know if it is possible to create an alert and apply it to a time slot

Exemple: have an unsuccessful ssh connection between 00:00 and 06:00

Does anybody know if this is possible ?

Thanks for your feedback

(Jan Doberstein) #2

you would work with the processing pipelines to get this work.

the when condition would check on the time of the day and then you write a field alert and in the actuall alert you just check on the existance of the field.

Graylog Alerting pipelines
(smigal) #3

Thank you for your answer

Would it be possible to have a syntax to use for tchecking on the time

For exemple : tchecking between 00:00 and 06:00 every day

Thanks for your feedback

(system) closed #4

