# \#pipeline-rules

**URL:** https://community.graylog.org/tag/pipeline-rules/1.md

[Latest](https://community.graylog.org/latest.md) · [Categories](https://community.graylog.org/categories.md) · [Tags](https://community.graylog.org/tags.md)

---

## [Pipeline to stream](https://community.graylog.org/t/pipeline-to-stream/37550)

<div class="topic-metadata">

**Author:** [@igoriceg](https://community.graylog.org/u/igoriceg)\
**Replies:** 4\
**Last updated:** [September 3, 2026, 8:38am UTC](https://community.graylog.org/t/pipeline-to-stream/37550 "2026-09-03T08:38:24Z")

</div>

Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question. Don’t forget to select tags to help index your topic! 1. Describ…

---

## [Unable to force date field type inside my indexes](https://community.graylog.org/t/unable-to-force-date-field-type-inside-my-indexes/36936)

<div class="topic-metadata">

**Author:** [@Theoooooo](https://community.graylog.org/u/Theoooooo)\
**Replies:** 5\
**Last updated:** [February 6, 2026, 10:44am UTC](https://community.graylog.org/t/unable-to-force-date-field-type-inside-my-indexes/36936 "2026-02-06T10:44:06Z")

</div>

Hello everyone I’ve been struggling on this issue for the past few days and i’m seeking any recommandation or explaination on how i can fix this issue I currently have multiple ubuntu servers which are sending logs thr…

---

## [Asset Import (AD / M365) - How to enhance asset objects](https://community.graylog.org/t/asset-import-ad-m365-how-to-enhance-asset-objects/36913)

<div class="topic-metadata">

**Author:** [@rbnkng](https://community.graylog.org/u/rbnkng)\
**Replies:** 0\
**Last updated:** [January 29, 2026, 9:54am UTC](https://community.graylog.org/t/asset-import-ad-m365-how-to-enhance-asset-objects/36913 "2026-01-29T09:54:01Z")

</div>

Hi everyone, I’m currently looking into Asset Enrichment ( Asset Enrichment) and it’s working so far. My question is, how did you people get the respective IP / MAC address of the machine assets attached to the assets? …

---

## [Stream : stop stage after matching a rule](https://community.graylog.org/t/stream-stop-stage-after-matching-a-rule/36883)

<div class="topic-metadata">

**Author:** [@yannickBZH](https://community.graylog.org/u/yannickBZH)\
**Replies:** 3\
**Last updated:** [January 28, 2026, 10:08am UTC](https://community.graylog.org/t/stream-stop-stage-after-matching-a-rule/36883 "2026-01-28T10:08:31Z")

</div>

Hello! Does anyone know if it’s possible to exit a stage after a rule matches? If a message matches a rule, I don’t want the following rules in the same stage to be evaluated. Thanks for your help!

---

## [Pipeline rule processing unterstanding](https://community.graylog.org/t/pipeline-rule-processing-unterstanding/36897)

<div class="topic-metadata">

**Author:** [@panklit](https://community.graylog.org/u/panklit)\
**Replies:** 1\
**Last updated:** [January 27, 2026, 1:33pm UTC](https://community.graylog.org/t/pipeline-rule-processing-unterstanding/36897 "2026-01-27T13:33:35Z")

</div>

Hello, I’m mildly confused on how rules in a stage processed. Are they run in parallel or sequential? I tried the following: Stage 1 Rule A - Should match a message if it has one of the Event IDs rule "check\_active\_…

---

## [Does Graylog 7 gracefully handle improper keys in flatten\_json?](https://community.graylog.org/t/does-graylog-7-gracefully-handle-improper-keys-in-flatten-json/36872)

<div class="topic-metadata">

**Author:** [@WildHunter854](https://community.graylog.org/u/WildHunter854)\
**Replies:** 0\
**Last updated:** [January 20, 2026, 10:58am UTC](https://community.graylog.org/t/does-graylog-7-gracefully-handle-improper-keys-in-flatten-json/36872 "2026-01-20T10:58:07Z")

</div>

1. Describe your incident: Hello folks, I need your help prior to opening a github issue, because our installation is fairly old (unmaintained 6.1) and we don’t have the possibility to check on a 7.0 Graylog instance i…

---

## [Correlating events from multiple streams](https://community.graylog.org/t/correlating-events-from-multiple-streams/36437)

<div class="topic-metadata">

**Author:** [@Miki](https://community.graylog.org/u/Miki)\
**Replies:** 1\
**Last updated:** [October 13, 2025, 2:23pm UTC](https://community.graylog.org/t/correlating-events-from-multiple-streams/36437 "2025-10-13T14:23:03Z")

</div>

Hi everyone, I’m using the free version of Graylog 6.3.3. Is there a way to create an alert that triggers only if both of these log events occur (from different streams) within 5 minutes? Stream AD → winlogbeat\_even…

---

## [Pipeline rule -\> when -\> "grok().matches == true" vs. "grok\_exists()"](https://community.graylog.org/t/pipeline-rule-when-grok-matches-true-vs-grok-exists/36271)

<div class="topic-metadata">

**Author:** [@schneich](https://community.graylog.org/u/schneich)\
**Replies:** 4\
**Last updated:** [September 1, 2025, 7:34am UTC](https://community.graylog.org/t/pipeline-rule-when-grok-matches-true-vs-grok-exists/36271 "2025-09-01T07:34:14Z")

</div>

Dear community, I am using Graylog 6.3.2 (docker) to gather all sorts of log data in my homelab. I have recently switched my Unifi USG-3P for a UCG-Ultra. My old pipeline rules need some love to work again. Unifi send…

---

## [Geo pipeline tips error](https://community.graylog.org/t/geo-pipeline-tips-error/36208)

<div class="topic-metadata">

**Author:** [@taoyang987](https://community.graylog.org/u/taoyang987)\
**Replies:** 3\
**Last updated:** [August 13, 2025, 1:06am UTC](https://community.graylog.org/t/geo-pipeline-tips-error/36208 "2025-08-13T01:06:08Z")

</div>

Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question. Don’t forget to select tags to help index your topic! accord…

---

## [Graylog Pipeline Rule GROK Pattern problems](https://community.graylog.org/t/graylog-pipeline-rule-grok-pattern-problems/36112)

<div class="topic-metadata">

**Author:** [@jvm](https://community.graylog.org/u/jvm)\
**Replies:** 1\
**Last updated:** [July 29, 2025, 8:05pm UTC](https://community.graylog.org/t/graylog-pipeline-rule-grok-pattern-problems/36112 "2025-07-29T20:05:28Z")

</div>

Hello everyone, I am new to GROK patterns, and I am currently struggling with implementing a pipeline rule and using GROK to extract data to fields. I am using a grok debugger, and in the debugger my GROK pattern works…

---

## [Pensando / switch logging multiple lines](https://community.graylog.org/t/pensando-switch-logging-multiple-lines/36077)

<div class="topic-metadata">

**Author:** [@nieuwenampsen](https://community.graylog.org/u/nieuwenampsen)\
**Replies:** 1\
**Last updated:** [July 29, 2025, 4:06pm UTC](https://community.graylog.org/t/pensando-switch-logging-multiple-lines/36077 "2025-07-29T16:06:19Z")

</div>

Hello, I’m using the free version of Graylog and running into an issue. Pensando is sending its output to Graylog, but often there are 3 log entries combined into a single message. I’ve tried several things (with pipel…

---

## [Pipeline rule: Unable to route messages to another stream](https://community.graylog.org/t/pipeline-rule-unable-to-route-messages-to-another-stream/36045)

<div class="topic-metadata">

**Author:** [@alst](https://community.graylog.org/u/alst)\
**Replies:** 3\
**Last updated:** [July 18, 2025, 8:44pm UTC](https://community.graylog.org/t/pipeline-rule-unable-to-route-messages-to-another-stream/36045 "2025-07-18T20:44:44Z")

</div>

Hello, I’m trying to route some messages to a separate stream using a pipeline rule. Do you have any idea why this doesn’t work? rule "Route to Extra Stream" when regex("Folders\_\\\\d+", regex\_replace("(\[^:\\\\s\]+)\\\\s\*…

---

## [Random OTX Timeout with active subscribrion](https://community.graylog.org/t/random-otx-timeout-with-active-subscribrion/36016)

<div class="topic-metadata">

**Author:** [@coffee\_is\_life](https://community.graylog.org/u/coffee_is_life)\
**Replies:** 0\
**Last updated:** [July 16, 2025, 10:07am UTC](https://community.graylog.org/t/random-otx-timeout-with-active-subscribrion/36016 "2025-07-16T10:07:53Z")

</div>

I have an active subscription at alienvault otx. most of the times the query is ok and i get the data. But on some request the data-adapter having a timeout. if i copy the failed ip into my test-lookup from lookup-tab…

---

## [Pipeline rule editor error when updating rules](https://community.graylog.org/t/pipeline-rule-editor-error-when-updating-rules/35561)

<div class="topic-metadata">

**Author:** [@elster](https://community.graylog.org/u/elster)\
**Replies:** 23\
**Last updated:** [July 11, 2025, 7:59am UTC](https://community.graylog.org/t/pipeline-rule-editor-error-when-updating-rules/35561 "2025-07-11T07:59:59Z")

</div>

Hi everyone! I hope someone can help. 1. Describe your incident: There’s an error when updating pipeline rules. I can create new rules with the rule editor from scratch just fine but as soon as I want to update a rule …

---

## [Replace "logcheck" by Graylog?](https://community.graylog.org/t/replace-logcheck-by-graylog/35887)

<div class="topic-metadata">

**Author:** [@ralfbergs](https://community.graylog.org/u/ralfbergs)\
**Replies:** 0\
**Last updated:** [June 23, 2025, 7:20am UTC](https://community.graylog.org/t/replace-logcheck-by-graylog/35887 "2025-06-23T07:20:03Z")

</div>

1. Purpose: I’m looking into replacing “logcheck” by Graylog. Currently I’m using “logcheck” on my Debian bare-metal server to become aware of events of interest. I’ve created an extensive regexp pattern list to suppres…

---

## [Unable to Implement a Simple Pipeline Rule to Manipulate the source Field to Reflect the Hostname in the message Field](https://community.graylog.org/t/unable-to-implement-a-simple-pipeline-rule-to-manipulate-the-source-field-to-reflect-the-hostname-in-the-message-field/35820)

<div class="topic-metadata">

**Author:** [@kwakalack](https://community.graylog.org/u/kwakalack)\
**Replies:** 3\
**Last updated:** [June 9, 2025, 4:36pm UTC](https://community.graylog.org/t/unable-to-implement-a-simple-pipeline-rule-to-manipulate-the-source-field-to-reflect-the-hostname-in-the-message-field/35820 "2025-06-09T16:36:29Z")

</div>

Hello community, I’m having some issues with pipeline rules and hoping I can find some assistance please. My stage 0 rule is working fine and I have it set to continue processing on next stage when none or more rules o…

---

## [Zyxel USG FLEX input does not work correctly](https://community.graylog.org/t/zyxel-usg-flex-input-does-not-work-correctly/35543)

<div class="topic-metadata">

**Author:** [@warderus](https://community.graylog.org/u/warderus)\
**Replies:** 2\
**Last updated:** [May 6, 2025, 5:51pm UTC](https://community.graylog.org/t/zyxel-usg-flex-input-does-not-work-correctly/35543 "2025-05-06T17:51:41Z")

</div>

Hey, everybody! I faced a problem with parsing logs from Zyxel USG FLEX. Logs arrive on 5555, as you can see from TCPdump capture, but after that they disappear and are not written to graylog. From searches I realized t…

---

## [How can I add a nested json? All I can find is stuff about parsing json but I want to create one](https://community.graylog.org/t/how-can-i-add-a-nested-json-all-i-can-find-is-stuff-about-parsing-json-but-i-want-to-create-one/35371)

<div class="topic-metadata">

**Author:** [@Gorf](https://community.graylog.org/u/Gorf)\
**Replies:** 1\
**Last updated:** [April 4, 2025, 10:31am UTC](https://community.graylog.org/t/how-can-i-add-a-nested-json-all-i-can-find-is-stuff-about-parsing-json-but-i-want-to-create-one/35371 "2025-04-04T10:31:45Z")

</div>

I have a badly formatted message from a network device that I get from syslog. I’ve got a tidy little pipeline rule that gets it all formatted. But what I really want, and can’t figure out how to do is the following. Cur…

---

## [Issue's with Log Enrichment](https://community.graylog.org/t/issues-with-log-enrichment/35174)

<div class="topic-metadata">

**Author:** [@FlashComputingSec](https://community.graylog.org/u/FlashComputingSec)\
**Replies:** 1\
**Last updated:** [March 17, 2025, 10:23am UTC](https://community.graylog.org/t/issues-with-log-enrichment/35174 "2025-03-17T10:23:54Z")

</div>

To the Graylog community at large, I’ve been having issues with log enrichment. Specifically, I’ve been having issues with getting geolocation data to properly be enriched with my logs. And the goal and need for this dat…

---

## [Mapping fields of a string message](https://community.graylog.org/t/mapping-fields-of-a-string-message/35103)

<div class="topic-metadata">

**Author:** [@pcnr](https://community.graylog.org/u/pcnr)\
**Replies:** 2\
**Last updated:** [March 3, 2025, 3:35pm UTC](https://community.graylog.org/t/mapping-fields-of-a-string-message/35103 "2025-03-03T15:35:25Z")

</div>

Good morning everyone, I’m new to Graylog and I’m struggling a bit with the parsing of messages. I tried to read some documentation and various posts/videos and I understood that I should use pipelines instead of extract…

---

## [Set field my pipeline don't work](https://community.graylog.org/t/set-field-my-pipeline-dont-work/35002)

<div class="topic-metadata">

**Author:** [@peaile](https://community.graylog.org/u/peaile)\
**Replies:** 7\
**Last updated:** [February 25, 2025, 10:52am UTC](https://community.graylog.org/t/set-field-my-pipeline-dont-work/35002 "2025-02-25T10:52:23Z")

</div>

1. Describe your incident: I receive logs from my firewall which follow this pattern : { "gl2\_accounted\_message\_size": 740, "gl2\_receive\_timestamp": "2025-02-21 15:40:01.265", "level": 6, "gl2\_remote\_ip": "168.…

---

## [Need Assistance with GeoIP and Pipeline](https://community.graylog.org/t/need-assistance-with-geoip-and-pipeline/35016)

<div class="topic-metadata">

**Author:** [@FlashComputingSec](https://community.graylog.org/u/FlashComputingSec)\
**Replies:** 5\
**Last updated:** [February 24, 2025, 10:44pm UTC](https://community.graylog.org/t/need-assistance-with-geoip-and-pipeline/35016 "2025-02-24T22:44:56Z")

</div>

Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question. Don’t forget to select tags to help index your topic! 1. Describ…

---

## [Parsing json log from eset console](https://community.graylog.org/t/parsing-json-log-from-eset-console/34873)

<div class="topic-metadata">

**Author:** [@freud44](https://community.graylog.org/u/freud44)\
**Replies:** 1\
**Last updated:** [February 6, 2025, 2:41pm UTC](https://community.graylog.org/t/parsing-json-log-from-eset-console/34873 "2025-02-06T14:41:32Z")

</div>

Don’t forget to select tags to help index your topic! 1. Describe your incident: I’m ingesting logs from my antivirus (eset), and I’m not able to parse the message value content which seems to be a json. 2. Describe y…

---

## [Graylog Pipeline rule with IPV6 not working](https://community.graylog.org/t/graylog-pipeline-rule-with-ipv6-not-working/34683)

<div class="topic-metadata">

**Author:** [@AckDeGo](https://community.graylog.org/u/AckDeGo)\
**Replies:** 8\
**Last updated:** [January 30, 2025, 4:04pm UTC](https://community.graylog.org/t/graylog-pipeline-rule-with-ipv6-not-working/34683 "2025-01-30T16:04:02Z")

</div>

1. Describe your incident: ipv6 pipeline rule not work on field type IP. 2. Describe your environment: OS Information: docker Package Version: 6.1.4 Service logs, configurations, and environment variables: C…

---

## [ASN/Subnet Lookup](https://community.graylog.org/t/asn-subnet-lookup/34694)

<div class="topic-metadata">

**Author:** [@TechWizz](https://community.graylog.org/u/TechWizz)\
**Replies:** 0\
**Last updated:** [January 15, 2025, 10:13pm UTC](https://community.graylog.org/t/asn-subnet-lookup/34694 "2025-01-15T22:13:12Z")

</div>

I have been able to use GeoIP to look up the locations of IP addresses. I have my pipeline set up where it assigns the caught IP as its own variable. I noticed that when setting up the Geo-Location Processor, there is an…

---

## [Creating GROK rule to parse across multiline log](https://community.graylog.org/t/creating-grok-rule-to-parse-across-multiline-log/34638)

<div class="topic-metadata">

**Author:** [@huimin](https://community.graylog.org/u/huimin)\
**Replies:** 0\
**Last updated:** [January 10, 2025, 8:39am UTC](https://community.graylog.org/t/creating-grok-rule-to-parse-across-multiline-log/34638 "2025-01-10T08:39:19Z")

</div>

1. Describe your incident: I am trying to write a pipeline rule that will extract value based on a grok pattern and set field. Sample log: An account failed to log on. Subject: Security ID: NULL SID Account Name: …

---

## [Unifi USG-3P firewall rules and GROK pattern](https://community.graylog.org/t/unifi-usg-3p-firewall-rules-and-grok-pattern/34475)

<div class="topic-metadata">

**Author:** [@schneich1](https://community.graylog.org/u/schneich1)\
**Replies:** 7\
**Last updated:** [December 24, 2024, 11:27pm UTC](https://community.graylog.org/t/unifi-usg-3p-firewall-rules-and-grok-pattern/34475 "2024-12-24T23:27:50Z")

</div>

Dear community, It has been almost 2 years, since a last did some work on my Graylog. It is running in a docker container and I keep it up-to-date. (currently on version 6.1.3) I get the syslog messages from my Unifi U…

---

## [Errors/issues in pipeline rule builder: Invalid expression, not adding new field](https://community.graylog.org/t/errors-issues-in-pipeline-rule-builder-invalid-expression-not-adding-new-field/34237)

<div class="topic-metadata">

**Author:** [@marziglt](https://community.graylog.org/u/marziglt)\
**Replies:** 1\
**Last updated:** [November 20, 2024, 5:30pm UTC](https://community.graylog.org/t/errors-issues-in-pipeline-rule-builder-invalid-expression-not-adding-new-field/34237 "2024-11-20T17:30:36Z")

</div>

Using Graylog Open 6.1, we’re trying to parse the Category from an incoming log stream derived from the OpenSearch cluster log file. Sample message: servername file-osgraylog: \[2024-11-19T13:22:07,732\]\[INFO \]\[o.o.j.s.…

---

## [Parsing bitwise values](https://community.graylog.org/t/parsing-bitwise-values/34095)

<div class="topic-metadata">

**Author:** [@Zoddo](https://community.graylog.org/u/Zoddo)\
**Replies:** 0\
**Last updated:** [November 8, 2024, 3:18pm UTC](https://community.graylog.org/t/parsing-bitwise-values/34095 "2024-11-08T15:18:10Z")

</div>

Hello, I’m trying to parse a bitwise value from a Windows event log (values from this table) in Graylog 5.2.12 (upgrade to 6.1 is planned before the end of the year). I’d like to get something like that: 0x00001 = R 0…

---

## [How to use $message.message in Pipeline rule GUI](https://community.graylog.org/t/how-to-use-message-message-in-pipeline-rule-gui/33796)

<div class="topic-metadata">

**Author:** [@pdl-nico](https://community.graylog.org/u/pdl-nico)\
**Replies:** 0\
**Last updated:** [October 9, 2024, 8:25am UTC](https://community.graylog.org/t/how-to-use-message-message-in-pipeline-rule-gui/33796 "2024-10-09T08:25:16Z")

</div>

1. Describe your incident: I try to use the GUI to create pipeline rules but I can’t use $message.message in functions like ‘replace’ However it’s possible in the source code editor. Ho to refer to $message.message in…

[Next page](https://community.graylog.org/tag/pipeline-rules/1.md?match_all_tags=true&page=1&tags%5B%5D=pipeline-rules)
