i want to drop many messages when messages contain keyword like:
message 1: snmpd: truncating integer value > 32 bits
message 2: agetty: /dev/ttyS0: not a tty
here my pipeline rule
rule "Drop Message fw noise-2"
contains(to_string($message.message),"truncating") && contains(to_string($message.message), "agetty")
It look as though you are describing two messages coming through. Pipeline Rules only work on one message at a time. If you are licensed (Free if you use under 2GB a day) You can store message information in Graylog MongoDB instance for future message use - its not clear how you would correlate it from what what you have shown though. Is that what you mean?