How to create Stream Rule for containers


(RABOEUF) #1

Hello,
I begin on Graylog and I need help :slight_smile:
I would like to propose to my colleagues the logs that correspond to their project.
The project runs on different containers and it is easy to make the difference but how to create the associated rules?
Thx in advance

Jeremie


(Jochen) #2

What exactly are you trying to accomplish?
You need to elaborate a little bit on what your goals are because that’s not clear to me from your first post.


(RABOEUF) #3

the goal is to give a view to certain logs for a user group, these logs must contain only certain things, eg: only the logs of the container "test"
Thx :slight_smile:


(Jochen) #4

You can do that with Streams: http://docs.graylog.org/en/2.3/pages/streams.html

All you need is a field in the message which contains the container ID (or another unique value which can be mapped to the container or project).


(RABOEUF) #5

I tried but I think I missing something.
In “All messages” I have this message and I need to create a Stream for “vision360”


(RABOEUF) #6

I created this Stream rule
image

but I don’t have a messagein my stream :frowning:


(Jochen) #7

Is there a field named “vision360” in your messages? I don’t see one in the example message you’ve posted.


(RABOEUF) #8

no but i want to get all the logs from the vision360 containers


(Jochen) #9

Then you either need to extract the string “vision360” into a custom message field or match another field in your stream rule.


(RABOEUF) #10

Ok but how ?
I just want to have a logs of container_name vision360


(Jochen) #11

If I were you, I’d probably split the container_name field on the - character, write the first result (e. g. “vision360_prod”) to a custom field (named “environment” or something like that), and match that in my stream rules.


(RABOEUF) #12

ok, it’s working now but is it possible to have in a same rule few value, separate with “,” or “;” ?


(Jochen) #13

No, that’s not possible. You need to create individual stream rules.


(RABOEUF) #14

yes I thought well :slight_smile:
in any case thank you very much for your availability
I would have more questions later


How to How you create custom field
(RABOEUF) #15

Sorry but I have just for the moment create a simple rule like that
image
It’s working but I have some case or is not
How you create custom field ?


(Jochen) #16

You can use either extractors or the processing pipelines for this.

http://docs.graylog.org/en/2.3/pages/extractors.html
http://docs.graylog.org/en/2.3/pages/pipelines.html


(system) #17

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.