# Rules from Stream strange work

**URL:** <https://community.graylog.org/t/rules-from-stream-strange-work/13879>\
**Category:** Graylog Central (peer support)\
**Created:** [February 10, 2020, 11:05am UTC](https://community.graylog.org/t/rules-from-stream-strange-work/13879 "2020-02-10T11:05:32Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![JackRepos2018](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jackrepos2018/32/5896_2.png) [@JackRepos2018](https://community.graylog.org/u/JackRepos2018)\
**Post date:** [February 10, 2020, 11:05am UTC](https://community.graylog.org/t/rules-from-stream-strange-work/13879/1 "2020-02-10T11:05:32Z")

</div>

Guys help please!!! My chief wants killing me ))). Problem is next…  
I set regular expression rules in the stream. Then I connected the stream in condition, where I turned on the telegram notification - now the problem is: Each event in the request, it sends to telegrams and this is too much, we need to respond only to those that I specified in the rules + so that it sends one at a time , and not every second, for example, it reached 5 messages, sent to telegram 1, reached 20 messages, sent to telegram 1. For some reason, after I updated the new versions, everything works poorly, maybe I need to completely recreate the streams with the rules … .

Thanks if you help !!!

 ![graylog-problem1](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/0/08ad4a3ab1c8f24887fe707bd710262d1ec946b8.png)

---

<div class="post-metadata">

**Author:** ![konrad](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/konrad/32/1661_2.png) [@konrad](https://community.graylog.org/u/konrad)\
**Post date:** [February 10, 2020, 11:44am UTC](https://community.graylog.org/t/rules-from-stream-strange-work/13879/2 "2020-02-10T11:44:13Z")

</div>

Hi @JackRepos2018,

from what I am reading you try to solve something with streams which should be solved with Alerts. Please take your time and have a look at alerts. I think it would also makes sense to upgrade to 3.2 which would help you with the multiple condition problem. But I am not 100% sure.

In Alerts you can have a grace period, which should prevent you from sending a notification for every incoming alert.

I might get you wrong so please clarify if I missunderstood your problem.

Best regards,  
Konrad

---

<div class="post-metadata">

**Author:** ![JackRepos2018](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jackrepos2018/32/5896_2.png) [@JackRepos2018](https://community.graylog.org/u/JackRepos2018)\
**Post date:** [February 10, 2020, 11:47am UTC](https://community.graylog.org/t/rules-from-stream-strange-work/13879/3 "2020-02-10T11:47:39Z")

</div>

Yeah i tried to understood - work my rules from stream or not with regular expressions. Our version is 3.2 now!!!  
And about Alerts Grace period - i set 0. And 1 in Message Backlog. So maybe i need Grace period set up for are hours ? But then we received many alerts too???

---

<div class="post-metadata">

**Author:** ![JackRepos2018](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jackrepos2018/32/5896_2.png) [@JackRepos2018](https://community.graylog.org/u/JackRepos2018)\
**Post date:** [February 10, 2020, 12:47pm UTC](https://community.graylog.org/t/rules-from-stream-strange-work/13879/4 "2020-02-10T12:47:20Z")

</div>

Maybe who can connecting to my RDP screen… And change settings on One of my Alert devices to definition that send One message after received in stream device…

 ![graylog-problem2](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/f/fcdcb4c7b14603b9fdae4c5e2b0c826099ae12b6.png)

---

<div class="post-metadata">

**Author:** ![JackRepos2018](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jackrepos2018/32/5896_2.png) [@JackRepos2018](https://community.graylog.org/u/JackRepos2018)\
**Post date:** [February 10, 2020, 12:52pm UTC](https://community.graylog.org/t/rules-from-stream-strange-work/13879/5 "2020-02-10T12:52:51Z")

</div>

Next screen

 ![graylog-problem3](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/7/732c75d7d9926475b20feba6150bf2f1bdb2fbf1.png)

---

<div class="post-metadata">

**Author:** ![JackRepos2018](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jackrepos2018/32/5896_2.png) [@JackRepos2018](https://community.graylog.org/u/JackRepos2018)\
**Post date:** [February 10, 2020, 12:56pm UTC](https://community.graylog.org/t/rules-from-stream-strange-work/13879/6 "2020-02-10T12:56:54Z")

</div>

Please look at the second screen where on right side we see many Events sNMP…linkDown, for 1 hour we have many messages from tcp ports, and that every message alerting to telegram. Our tasks is:  
This message from ports send once…

---

<div class="post-metadata">

**Author:** ![JackRepos2018](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jackrepos2018/32/5896_2.png) [@JackRepos2018](https://community.graylog.org/u/JackRepos2018)\
**Post date:** [February 17, 2020, 4:36pm UTC](https://community.graylog.org/t/rules-from-stream-strange-work/13879/7 "2020-02-17T16:36:03Z")

</div>

Did you not have ideas anybody about my topic? Please maybe who knows some really worked solution in settings of GrayLog Alert

---

<div class="post-metadata">

**Author:** ![konrad](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/konrad/32/1661_2.png) [@konrad](https://community.graylog.org/u/konrad)\
**Post date:** [February 24, 2020, 8:22am UTC](https://community.graylog.org/t/rules-from-stream-strange-work/13879/8 "2020-02-24T08:22:25Z")

</div>

Hi @JackRepos2018,

I did not got a notification that you answered. So from what I understand you try to get a notification per port once right? This not quite possible. But please have a look at what I described here:

> [@Unique notification](https://community.graylog.org/t/unique-notification/13797/6):
>
> @gertz I had now a longer conversation with one of the developers. This gonna be a rough ride, so fasten your seat belt. I might have a solution where you would get one email for every unique indecent, which you could configure a grace period for a couple of hours/days. That way the noise in the messages would be reduced. I assume from your previous messages that you already extracted the ID in to its own message field called CN. If now then you should do so now. Create/Edit the event definit…

This will reduce the amount of messages send for one field.

Best regards,  
Konrad

---

<div class="post-metadata">

**Author:** ![JackRepos2018](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jackrepos2018/32/5896_2.png) [@JackRepos2018](https://community.graylog.org/u/JackRepos2018)\
**Post date:** [February 24, 2020, 8:50am UTC](https://community.graylog.org/t/rules-from-stream-strange-work/13879/9 "2020-02-24T08:50:51Z")

</div>

Well @konrad, then one last question, in Stream I set up the rules according to which the event should look at my request and not send some noisy messages from devices, but they are still sent, I can’t understand what’s wrong, look at the screenshot please

 ![graylog example reules](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/0/03104c105adee06e366982ca0a11f18634b38166.png)

---

<div class="post-metadata">

**Author:** ![konrad](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/konrad/32/1661_2.png) [@konrad](https://community.graylog.org/u/konrad)\
**Post date:** [February 25, 2020, 8:45am UTC](https://community.graylog.org/t/rules-from-stream-strange-work/13879/10 "2020-02-25T08:45:28Z")

</div>

@JackRepos2018,

I do not understand your question? Can you please be a bit more clear what is not working?

Best regards,  
Konrad

---

<div class="post-metadata">

**Author:** ![JackRepos2018](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jackrepos2018/32/5896_2.png) [@JackRepos2018](https://community.graylog.org/u/JackRepos2018)\
**Post date:** [February 26, 2020, 8:50am UTC](https://community.graylog.org/t/rules-from-stream-strange-work/13879/11 "2020-02-26T08:50:25Z")

</div>

@konrad. Ok, Please look at the screen. I talk about those rules. I create it and want that they work, but they didn’t worked and regular expressions too, All messages in those rules we received on telegram and email, but I would like to exclude some with regular expression help!!! Question - Why rules don’t work in the streams maybe you know?

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/2/284396aeb8ecf7255e983846ee3e9d6a71aa4536.png)

Our devices is Juniper.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [March 11, 2020, 8:50am UTC](https://community.graylog.org/t/rules-from-stream-strange-work/13879/12 "2020-03-11T08:50:29Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
