Stream Rule - is wildcard possible


#1

Good day,

I’ve been trying to figure out if there is a way to create a stream rule based on a string within the message body.

I’ve looked through the internet and haven’t been able to find anything.

I’m able to sort my results on the elastic search with wildcard within the message body however for stream rule it appears to be a different set of rules.

I have snort setup to pipe information to our graylog and ultimately I would like to set email alerts on certain information coming from snort.

Please help. thanks.

Johnny


(Sachin) #2

You can use the “contain” filter for your stream rules.streamedit


#3

Hi Sachin,

thanks. Which version of graylog are you using? I don’t have contain as a selection? I’m using graylog 2.0

screenshot

Cheers,
Johnny


(Jochen) #4

The “contains” condition has been added in Graylog 2.1.2.

https://github.com/Graylog2/graylog2-server/pull/3037


(Sachin) #5

Use 2.3
There are many cool enhancements made.


#6

Thanks,

I’m sold on the idea of new enhancements.

=)


(system) #7

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.