following rule should just drop the message if the log level is “7”:
rule "drop_level7_netscaler" when syslog_level($message.level) == "7" then drop_message(); end
Somehow this does not work.
Yes, the rule is part of a pipeline, which is attached to a stream.
I use Graylog 2.2.3.
The pipeline processor is active.
Thanks in advance for any help.