1. Describe your incident:
trying to create stream rule based off the src_ip, wish to have all messages with a src_ip of 192.168. moved into stream, tried using the match regular expression, selected the src_ip field , selected match regular expression, for value, tried various incarnations of , 192\.168\..*\..*
seems that the rules test says it worked however messages are not being routed into stream…
2. Describe your environment:
-
OS Information: linux
-
Package Version:Graylog 5.2.3+9aee303
-
Service logs, configurations, and environment variables:
3. What steps have you already taken to try and solve the problem?
tried different incarnations of 192.168....
4. How can the community help?
i’m thinging the wild cards may be the issue , eventually i was trying to create a incoming stream and a out going stream…
Helpful Posting Tips: Tips for Posting Questions that Get Answers [Hold down CTRL and link on link to open tips documents in a separate tab]