Hello
I am using Graylog 4.1.x. I log brute force attacks from Mikrotik router. I am sending all of these logs to Graylog. So far everything is ok. However, when I create an alarm, I cannot see the ip address in the message or the entire message in the incoming e-mails.
Example_log:
rt0 login failure for user admin from 10.0.0.100 via ssh
Below is my email and html template.
--- [Event Definition] ---------------------------
Title: ${event_definition_title}
Description: ${event_definition_description}
Type: ${event_definition_type}
--- [Event] --------------------------------------
EventID: ${event.id}
EventMessage: ${event.message}
Timestamp: ${event.timestamp}
Message: ${message.message}
OB1: ${message.fields.full_message}
Source: ${event.source}
User: ${source.user}
Key: ${event.key}
Priority: ${event.priority}
Alert: ${event.alert}
Timestamp Processing: ${event.timestamp}
Timerange Start: ${event.timerange_start}
Timerange End: ${event.timerange_end}
Fields:
${foreach event.fields field} ${field.key}: ${field.value}
${foreach backlog message}${message.fields.src_ip}
${if backlog}
--- [Backlog] ------------------------------------
Last messages accounting for this alert:
${foreach backlog message}
User: ${source.user}
${message.fields.EventID}
${message.fields.TargetUserName}
${message.fields.SubjectUserName}
${if backlog}${foreach backlog message}
${message.fields.EventID}
${message.fields.TargetUserName}
${message.fields.SubjectUserName}
--- Raw Message ---
${message.message}
${end}${else}${end}
${message}
${end}
${end}
${end}
${end}