Grupping messages


(dsever) #1

Hi

Is it possible to accomplish kind of log aggregation using graylog. For instance I have 300 same messages (same src and dest ip) from ASA, and don’t waste my disk by storing individual items.
So my solution would be counting number of same messages (distinction by src ip and dest) (kind of deduplication) and write only one message that has additional field count? Is is possible to do by using rules?

Any examples would be great to have.

Thanks
Dubravko


(Jan Doberstein) #2

with the given vanilla Graylog that is not possible. You would need to write your own plugin for that or use some kind of third party plugin.

regards
Jan


(system) #3

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.