hi, i am new to graylog, I have installed the system and it is ingesting logs without issue. i am setting up some basic alerts but i am confused on how to include message data in an alert log. i am using sidecar with winlogbeat. I have created an alert for “locked out user” and i would like to include
I don’t recall the explanation off -hand (at home, all the cool stuff is at work) but this should pull the data from all messages within your backlog time period.
That is the format I have in my subject line and it works just fine… What version of Graylog are you on? The only difference I can see is mine does not have spaces. Here it is verbatim:
i don;t see a difference, but i am hoping this will work, i am waiting for the event to occur for a test.
is there something “special” about the variable that it needs to be treated differently? I have been doing a lot of searching, i see in some posts people use $$ instead of $…do you know why?
ug, ok, i figured out my issue, i missed this step in creating the event. I had the number of backlog messages set to 0, so …of course… there were no messages to pull variables from