# Graylog in a Nutshell (Diagram)

**URL:** <https://community.graylog.org/t/graylog-in-a-nutshell-diagram/24217>\
**Category:** Miscellaneous\
**Created:** [June 8, 2022, 3:50pm UTC](https://community.graylog.org/t/graylog-in-a-nutshell-diagram/24217 "2022-06-08T15:50:45Z")\
**Posts on this page:** 5\
**Page:** 2

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [June 22, 2022, 10:57pm UTC](https://community.graylog.org/t/graylog-in-a-nutshell-diagram/24217/21 "2022-06-22T22:57:17Z")

</div>

@WavedirectTel

> [@WavedirectTel](#):
>
> Wouldn’t be output from the Stream “Rules”? Or just Streams (All)?

Sorry for the delay, I was on Va-ca, as my understanding this would be on Streams and each stream could have a different output and type.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/5/56aee735119e1236497cb20933f1fa7b90c71ed4.png)

---

<div class="post-metadata">

**Author:** ![Arie](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/arie/32/8094_2.png) [@Arie](https://community.graylog.org/u/Arie)\
**Post date:** [July 13, 2022, 6:43pm UTC](https://community.graylog.org/t/graylog-in-a-nutshell-diagram/24217/22 "2022-07-13T18:43:07Z")

</div>

In my opinion and how one configures alerts that part of the system looks in the database / indice directly as one configures the period and search query that one configures.

The system then schedules the alert query’s. That is how it seams to be implemented in version 4.x. Tho older versions seamed to work a bit differently.

---

<div class="post-metadata">

**Author:** ![nisow95612](https://avatars.discourse-cdn.com/v4/letter/n/3d9bf3/32.png) [@nisow95612](https://community.graylog.org/u/nisow95612)\
**Post date:** [August 30, 2022, 8:48am UTC](https://community.graylog.org/t/graylog-in-a-nutshell-diagram/24217/23 "2022-08-30T08:48:58Z")

</div>

Yup, alerts are effectively cronjobs that periodically search elastic. I wish there was a way to hook some of my alerts directly in the processing flow or better maybe allow pipeline rules to create real-time alerts?

---

<div class="post-metadata">

**Author:** ![WavedirectTel](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/wavedirecttel/32/11946_2.png) [@WavedirectTel](https://community.graylog.org/u/WavedirectTel)\
**Post date:** [August 30, 2022, 12:54pm UTC](https://community.graylog.org/t/graylog-in-a-nutshell-diagram/24217/24 "2022-08-30T12:54:35Z")

</div>

Dunno I haven’t got that far with it yet. But I am enjoying the hell out of Graylog so far. So much we can do but so much to learn!

---

<div class="post-metadata">

**Author:** ![ihe](https://avatars.discourse-cdn.com/v4/letter/i/a88e57/32.png) [@ihe](https://community.graylog.org/u/ihe)\
**Post date:** [August 30, 2022, 2:55pm UTC](https://community.graylog.org/t/graylog-in-a-nutshell-diagram/24217/25 "2022-08-30T14:55:20Z")

</div>

I still think lookup tables are (mostly) used in pipelines. Those can be used in decorators afterwards, but the main use at least to me is in pipelines.

[Previous page](https://community.graylog.org/t/graylog-in-a-nutshell-diagram/24217.md?page=1)
