Graylog monitor its own logs

You can either modify the messages in question in a pipeline rule (e. g. with rename_field()) or store these messages in a stream with a custom index set (with its own index mapping) and remove them from the “All messages” stream, see http://docs.graylog.org/en/2.4/pages/streams.html.

1 Like