# Graylog Research

**URL:** <https://community.graylog.org/t/graylog-research/4534>\
**Category:** Graylog Central (peer support)\
**Created:** [March 12, 2018, 7:50pm UTC](https://community.graylog.org/t/graylog-research/4534 "2018-03-12T19:50:15Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rodrigogriffo](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/rodrigogriffo/32/1949_2.png) [@rodrigogriffo](https://community.graylog.org/u/rodrigogriffo)\
**Post date:** [March 12, 2018, 7:50pm UTC](https://community.graylog.org/t/graylog-research/4534/1 "2018-03-12T19:50:15Z")

</div>

Sorry for english but I use google translate.

I started using Graylog in a short time especially to extract logs from pfSense Firewall.

I have a pfSense that acts as a Captive Portal for a college and I am needing to log the access log for a while. I made some extracts and it is taking care of me, I used the GROK that is available in the marketplace for pfSense and everything is alright.

Now I have to do some research so that I can get back what I want.

I did a search to ONLY deliver the users logged in with the date / time and ip and this is ok.

I did using the SPLIT of the “message” and when it is necessary I do the following search: \_exists \_: “login\_user” AND NOT nginx

When I need to know an ip that was accessed I put: DestIP: “ip of destination”

I have my answers separated … now I would like to “join” the searches or I want to know which user accessed which ip

Ex. DestIP -\> login\_user

But I can not do it … I tried the following ways …

DestIP: “destination ip” AND \_exists \_: “login\_user”

\_exists \_: “destination ip” AND NOT nginx && DestIP: “destination ip”

I’ve tried it in other ways and still can not …

I ask for the help and thank you.

Att. Rodrigo Griffo

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [March 13, 2018, 9:42am UTC](https://community.graylog.org/t/graylog-research/4534/2 "2018-03-13T09:42:19Z")

</div>

Hej @rodrigogriffo

you might want to carefully read the part about searching of the documentation: [http://docs.graylog.org/en/2.4/pages/queries.html](http://docs.graylog.org/en/2.4/pages/queries.html)

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [March 13, 2018, 11:33am UTC](https://community.graylog.org/t/graylog-research/4534/3 "2018-03-13T11:33:04Z")

</div>

> [@rodrigogriffo](#):
>
> I have my answers separated … now I would like to “join” the searches or I want to know which user accessed which ip

Currently that’s not possible out of the box, but Graylog 3.0.0 might bring some features enabling these kind of queries.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [March 27, 2018, 11:33am UTC](https://community.graylog.org/t/graylog-research/4534/4 "2018-03-27T11:33:16Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
