# Noob ISO Pipeline Help

**URL:** <https://community.graylog.org/t/noob-iso-pipeline-help/16499>\
**Category:** Graylog Central (peer support)\
**Tags:** pipeline-rules\
**Created:** [July 23, 2020, 5:04pm UTC](https://community.graylog.org/t/noob-iso-pipeline-help/16499 "2020-07-23T17:04:25Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![poisedforflight](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/poisedforflight/32/6729_2.png) [@poisedforflight](https://community.graylog.org/u/poisedforflight)\
**Post date:** [July 23, 2020, 5:04pm UTC](https://community.graylog.org/t/noob-iso-pipeline-help/16499/1 "2020-07-23T17:04:25Z")

</div>

Hello all, I have been working with Graylog for about a month now so please bear with me if I end up using incorrect terminology. And thank you in advance for any help you can provide.

I have created a lookup table that converts hexadecimal error codes of a failed Windows NTLM Authentication attempt to a text description of that code. I have these logs flowing in and have created a lookup table to map the hex codes to the description I would like to see in the logs. When I test the data adapter it works as I would expect it to.

I believe I need to create a pipeline for this conversion to show in my log stream for Windows Security Event Logs. My basic logic is as follows, and I have attached a screenshot of an example message.

IF event\_id: 4776 AND keywords:[“Audit Failure”]  
THEN convert event\_data\_Status and the substatus Error Code: of message.

I want all of my other messages to also continue going to the stream. Could I please get some advice/examples on how to make this happen? Please let me know if there’s any additional info you need.

 ![2020-07-23_11-43-04](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/0/0b3cfc6695ce31c1223f24bebea738ab7a66e0d7.png)

---

<div class="post-metadata">

**Author:** ![tmacgbay](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/tmacgbay/32/3878_2.png) [@tmacgbay](https://community.graylog.org/u/tmacgbay)\
**Post date:** [July 23, 2020, 6:45pm UTC](https://community.graylog.org/t/noob-iso-pipeline-help/16499/2 "2020-07-23T18:45:09Z")

</div>

Here is a stab at the pipeline rule you can set up.

```
   rule "Win-Failure-4776-06a"
    when
        to_string($message.event_id) == "4776" &&
        contains(to_string($message.keywords),"Audit Failure")
        
    then
        let err_code_lu = lookup_value("HexErrTable",to_string($message.event_data_Status), 0);
        set_field("error_code", to_string(err_code_lu) );
        
        // in my opinion it is preferable to simply have a new field that contains your error code
        // overwriting the original event_data_Status could cause future issues
        
        //...but if you wanted overwrite:

        replace(to_string($message.message),to_string($message.event_data_Status), to_string(err_code_lu) );
        
        //now that you changed this one in the message, you can obliterate the original value with your lookup value.
        set_field("event_data_Status", to_string(err_code_lu));

    end
```

---

<div class="post-metadata">

**Author:** ![poisedforflight](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/poisedforflight/32/6729_2.png) [@poisedforflight](https://community.graylog.org/u/poisedforflight)\
**Post date:** [July 23, 2020, 6:49pm UTC](https://community.graylog.org/t/noob-iso-pipeline-help/16499/3 "2020-07-23T18:49:16Z")

</div>

Thank you, I’ll give that a try. If I want to add to instead of replace, what would that line look like?

---

<div class="post-metadata">

**Author:** ![tmacgbay](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/tmacgbay/32/3878_2.png) [@tmacgbay](https://community.graylog.org/u/tmacgbay)\
**Post date:** [July 23, 2020, 6:57pm UTC](https://community.graylog.org/t/noob-iso-pipeline-help/16499/4 "2020-07-23T18:57:42Z")

</div>

Assuming you mean add the translation to the original message next to the hex code?

let err\_trans = concat(to\_string($message.event\_data\_Status), " - translated: ");  
let err\_trans = concat(to\_string(err\_trans), to\_string(err\_code\_lu));

replace(to\_string($message.message),to\_string($message.event\_data\_Status), to\_string(err\_trans) );

---

<div class="post-metadata">

**Author:** ![poisedforflight](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/poisedforflight/32/6729_2.png) [@poisedforflight](https://community.graylog.org/u/poisedforflight)\
**Post date:** [July 23, 2020, 7:00pm UTC](https://community.graylog.org/t/noob-iso-pipeline-help/16499/5 "2020-07-23T19:00:16Z")

</div>

I actually mean create a new field in the message with the translated text.

Also, what does the 0 at the end of this line do? Check if it exists?

```auto
let err_code_lu = lookup_value("HexErrTable",to_string($message.event_data_Status), 0);

```

---

<div class="post-metadata">

**Author:** ![tmacgbay](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/tmacgbay/32/3878_2.png) [@tmacgbay](https://community.graylog.org/u/tmacgbay)\
**Post date:** [July 23, 2020, 7:07pm UTC](https://community.graylog.org/t/noob-iso-pipeline-help/16499/6 "2020-07-23T19:07:31Z")

</div>

I had that in the original - this sets the new field “error\_code” to be the results of the lookup.

> [@tmacgbay](#):
>
> `set_field("error_code", to_string(err_code_lu) );`

When you are writing the rules in the pipeline, the is a search on the right that gives you the basics of all the functions - for more detail you can look at the documentation online…

![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/0/00df20cd9084fd483a8832c1032912893372998a.png)

in this case the online is less descriptive .  
[https://docs.graylog.org/en/latest/pages/pipelines/functions.html#lookup-value](https://docs.graylog.org/en/latest/pages/pipelines/functions.html#lookup-value)

So you could change from 0 to something like “Not found in table!”

---

<div class="post-metadata">

**Author:** ![poisedforflight](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/poisedforflight/32/6729_2.png) [@poisedforflight](https://community.graylog.org/u/poisedforflight)\
**Post date:** [July 23, 2020, 8:04pm UTC](https://community.graylog.org/t/noob-iso-pipeline-help/16499/7 "2020-07-23T20:04:50Z")

</div>

Thank you so much, I appreciate you taking the time to help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [August 6, 2020, 8:04pm UTC](https://community.graylog.org/t/noob-iso-pipeline-help/16499/8 "2020-08-06T20:04:51Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
