# \#route-to-streampl

**URL:** https://community.graylog.org/tag/route-to-streampl/11.md

[Latest](https://community.graylog.org/latest.md) · [Categories](https://community.graylog.org/categories.md) · [Tags](https://community.graylog.org/tags.md)

---

## [Pipeline performance optimization and metrics](https://community.graylog.org/t/pipeline-performance-optimization-and-metrics/32528)

<div class="topic-metadata">

**Author:** [@CJRoss](https://community.graylog.org/u/CJRoss)\
**Replies:** 2\
**Last updated:** [May 28, 2024, 3:52pm UTC](https://community.graylog.org/t/pipeline-performance-optimization-and-metrics/32528 "2024-05-28T15:52:46Z")

</div>

Instead of attempting to upgrade my 5.x server I created a new 6.0 server and I’m going through and reworking my pipelines and rules now that I’m a bit more familiar with Graylog. I’m also working on learning the rule w…

---

## [Routing messages with pipelines, one large pipeline or multiple smaller ones?](https://community.graylog.org/t/routing-messages-with-pipelines-one-large-pipeline-or-multiple-smaller-ones/32258)

<div class="topic-metadata">

**Author:** [@josh.7](https://community.graylog.org/u/josh.7)\
**Replies:** 6\
**Last updated:** [April 30, 2024, 10:43am UTC](https://community.graylog.org/t/routing-messages-with-pipelines-one-large-pipeline-or-multiple-smaller-ones/32258 "2024-04-30T10:43:08Z")

</div>

I’ve got one input stream currently which will be ingesting at the very least hundreds, if not 1-2 thousand messages per second; i want to split these messages out into multiple, smaller streams as soon as possible, base…

---

## [Most efficient way to use pipelines for routing](https://community.graylog.org/t/most-efficient-way-to-use-pipelines-for-routing/32161)

<div class="topic-metadata">

**Author:** [@josh.7](https://community.graylog.org/u/josh.7)\
**Replies:** 1\
**Last updated:** [April 23, 2024, 4:43am UTC](https://community.graylog.org/t/most-efficient-way-to-use-pipelines-for-routing/32161 "2024-04-23T04:43:22Z")

</div>

Hello all, I’m wondering what the most efficient way to route messages to streams is; i’ve been using a pipeline, attached to one input stream, this pipeline has 6 different rules. Each rule evaluates a certain field, …

---

## [Rules for routing messages to different indexes](https://community.graylog.org/t/rules-for-routing-messages-to-different-indexes/31570)

<div class="topic-metadata">

**Author:** [@pagudo](https://community.graylog.org/u/pagudo)\
**Replies:** 8\
**Last updated:** [March 8, 2024, 8:55pm UTC](https://community.graylog.org/t/rules-for-routing-messages-to-different-indexes/31570 "2024-03-08T20:55:48Z")

</div>

1. Describe your incident: Hello everyone. I am starting with graylog and I would need someone to advise me on how to correctly route incoming messages. I have several Sophos XG and UTM firewalls. As the logs are diff…

---

## [Issue with AzureAD Pipeline Rule - Client IP for Map](https://community.graylog.org/t/issue-with-azuread-pipeline-rule-client-ip-for-map/26719)

<div class="topic-metadata">

**Author:** [@DrunkMunki](https://community.graylog.org/u/DrunkMunki)\
**Replies:** 10\
**Last updated:** [November 30, 2022, 4:56am UTC](https://community.graylog.org/t/issue-with-azuread-pipeline-rule-client-ip-for-map/26719 "2022-11-30T04:56:35Z")

</div>

1. Describe your incident: I am trying to create a map of IP’s addresses of failed logins. I followed the guide here to setup GeoIP but the pipeline rule isnt finding the IP Address (ClientIP) The “Input” Extractor co…

---

## [Stream message do not show](https://community.graylog.org/t/stream-message-do-not-show/24558)

<div class="topic-metadata">

**Author:** [@ericwu](https://community.graylog.org/u/ericwu)\
**Replies:** 5\
**Last updated:** [July 1, 2022, 2:17am UTC](https://community.graylog.org/t/stream-message-do-not-show/24558 "2022-07-01T02:17:16Z")

</div>

Hi Guys, I saw the message was route to stream. But when I choice the stream and click search nothing will show ?

---

## [Raspberry Pi 4 home Graylog setup](https://community.graylog.org/t/raspberry-pi-4-home-graylog-setup/21038)

<div class="topic-metadata">

**Author:** [@dscryber](https://community.graylog.org/u/dscryber)\
**Replies:** 3\
**Last updated:** [May 16, 2022, 5:22pm UTC](https://community.graylog.org/t/raspberry-pi-4-home-graylog-setup/21038 "2022-05-16T17:22:02Z")

</div>

Comments? Posted by u/BourbonInExile in Reddit A bit of disclosure up front: I work at Graylog. I’ve been a software engineer on the Integrations team (mostly building Enterprise features like the O365 input and the…

---

## [Finding if a users IP changes (part 2)](https://community.graylog.org/t/finding-if-a-users-ip-changes-part-2/21680)

<div class="topic-metadata">

**Author:** [@darrinh](https://community.graylog.org/u/darrinh)\
**Replies:** 4\
**Last updated:** [November 5, 2021, 6:40pm UTC](https://community.graylog.org/t/finding-if-a-users-ip-changes-part-2/21680 "2021-11-05T18:40:21Z")

</div>

Description of your problem We want to raise an alarm if a VPN user’s IP changes over time. Description of steps you’ve taken to attempt to solve the issue Not sure how to proceed with solving the issue. Environmental …

---

## [Rename index set backing "All messages" stream?](https://community.graylog.org/t/rename-index-set-backing-all-messages-stream/21425)

<div class="topic-metadata">

**Author:** [@nisow95612](https://community.graylog.org/u/nisow95612)\
**Replies:** 14\
**Last updated:** [October 26, 2021, 4:51pm UTC](https://community.graylog.org/t/rename-index-set-backing-all-messages-stream/21425 "2021-10-26T16:51:27Z")

</div>

Hello graylog community, I have one more question this month: Per Create/Cycle index set to specific ID? I am naming our index templates like “logs\_r01m”, “logs\_r06m”, “logs\_r12m”. I am using stream filters to pick out…

---

## [Server.log Error for CSV Conversion](https://community.graylog.org/t/server-log-error-for-csv-conversion/21363)

<div class="topic-metadata">

**Author:** [@loggingone](https://community.graylog.org/u/loggingone)\
**Replies:** 7\
**Last updated:** [October 19, 2021, 5:47am UTC](https://community.graylog.org/t/server-log-error-for-csv-conversion/21363 "2021-10-19T05:47:26Z")

</div>

Noticed that a periodic error is presented in the logs. Here is a sample: ERROR o.g.i.c.CsvConverter \[processbufferprocessor-3\] Different number of columns in CSV data (24) and configured field names (23). Discarding i…

---

## [Use Contains in a pipeline rule with double quote](https://community.graylog.org/t/use-contains-in-a-pipeline-rule-with-double-quote/21454)

<div class="topic-metadata">

**Author:** [@Pourya](https://community.graylog.org/u/Pourya)\
**Replies:** 4\
**Last updated:** [October 14, 2021, 6:49am UTC](https://community.graylog.org/t/use-contains-in-a-pipeline-rule-with-double-quote/21454 "2021-10-14T06:49:27Z")

</div>

Hello I’ve tried to read up the docs and this forum before posting this but couldn’t find similar issue. I’m trying to implement a pipeline rule like below to route certain message based on a string. rule "New\_Route" …

---

## [Strange Pipelines behavior on Cluster](https://community.graylog.org/t/strange-pipelines-behavior-on-cluster/21383)

<div class="topic-metadata">

**Author:** [@SR\_CSV](https://community.graylog.org/u/SR_CSV)\
**Replies:** 4\
**Last updated:** [October 7, 2021, 12:54pm UTC](https://community.graylog.org/t/strange-pipelines-behavior-on-cluster/21383 "2021-10-07T12:54:33Z")

</div>

Strange Pipelines behavior on Cluster On my single node Graylog, I have build for every input an own index, so that the Windows logs has an own index, the Linux server has an own index and so on. I managed this with st…

---

## [Pipeline Gets No Traffic](https://community.graylog.org/t/pipeline-gets-no-traffic/21351)

<div class="topic-metadata">

**Author:** [@danmassa7](https://community.graylog.org/u/danmassa7)\
**Replies:** 19\
**Last updated:** [October 5, 2021, 9:06pm UTC](https://community.graylog.org/t/pipeline-gets-no-traffic/21351 "2021-10-05T21:06:38Z")

</div>

Pipeline Receiving No Messages I’m trying to use pipelines for the very first time! Fun. I have an input called vpn-msgs-5004. I can filter on these message with: gl2\_source\_input:60d1d5d5f611a86add34edac I have a S…

---

## [Trying to understand how the source field is populated](https://community.graylog.org/t/trying-to-understand-how-the-source-field-is-populated/21191)

<div class="topic-metadata">

**Author:** [@SnazzyBootMan](https://community.graylog.org/u/SnazzyBootMan)\
**Replies:** 6\
**Last updated:** [September 16, 2021, 9:24pm UTC](https://community.graylog.org/t/trying-to-understand-how-the-source-field-is-populated/21191 "2021-09-16T21:24:41Z")

</div>

Description of your problem So I am ingesting logs using fluentd running on an AWS ECS sidecar container. The fluentd container is using a type unix source to read from /var/run/fluent.sock. I was not initially setting …

---

## [Get Notification for Unknown Devices Connecting to a Network](https://community.graylog.org/t/get-notification-for-unknown-devices-connecting-to-a-network/21042)

<div class="topic-metadata">

**Author:** [@mattolan](https://community.graylog.org/u/mattolan)\
**Replies:** 9\
**Last updated:** [September 1, 2021, 11:40pm UTC](https://community.graylog.org/t/get-notification-for-unknown-devices-connecting-to-a-network/21042 "2021-09-01T23:40:42Z")

</div>

Is it possible to use Graylog to parse Syslog messages and compare devices connecting to the network with some sort of list to determine if they are known trusted clients? And then alert if the device isn’t in that list…

---

## [RAW Input with “Length-prefixed framing”](https://community.graylog.org/t/raw-input-with-length-prefixed-framing/20968)

<div class="topic-metadata">

**Author:** [@nisow95612](https://community.graylog.org/u/nisow95612)\
**Replies:** 5\
**Last updated:** [August 25, 2021, 7:32pm UTC](https://community.graylog.org/t/raw-input-with-length-prefixed-framing/20968 "2021-08-25T19:32:20Z")

</div>

Hello Graylog community, I’m trying to collect logs from Fortinet firewall boxes. Shortened example of on-the-wire log format: 204 \<190\>logver=604061879 devname="FG646" cfgattr="source\[factory-\>factory\\\]certificate\[-\>\\…

---

## [How to approach file rename alerting (Sysmon)](https://community.graylog.org/t/how-to-approach-file-rename-alerting-sysmon/20872)

<div class="topic-metadata">

**Author:** [@CypherBit](https://community.graylog.org/u/CypherBit)\
**Replies:** 3\
**Last updated:** [August 13, 2021, 9:18pm UTC](https://community.graylog.org/t/how-to-approach-file-rename-alerting-sysmon/20872 "2021-08-13T21:18:48Z")

</div>

I’d like to be alerted when one field doesn’t contain the value of a different field, but don’t know how to approach it at all. For example if Image: field does not contain what OriginalFileName contains I’d like to hav…

---

## [User logged in Outside Business Hours](https://community.graylog.org/t/user-logged-in-outside-business-hours/20690)

<div class="topic-metadata">

**Author:** [@gsmith](https://community.graylog.org/u/gsmith)\
**Replies:** 0\
**Last updated:** [July 29, 2021, 10:53pm UTC](https://community.graylog.org/t/user-logged-in-outside-business-hours/20690 "2021-07-29T22:53:37Z")

</div>

I have to give respect to @jan for showing me this. This became the most importent Pipeline we use in multiply environments. rule "Between 6 PM and 6 AM" when ( to\_long(to\_date($message.timestamp, "American/Chicago").h…

---

## [Pipeline route\_to\_stream not working](https://community.graylog.org/t/pipeline-route-to-stream-not-working/20580)

<div class="topic-metadata">

**Author:** [@smolit](https://community.graylog.org/u/smolit)\
**Replies:** 4\
**Last updated:** [July 27, 2021, 11:57am UTC](https://community.graylog.org/t/pipeline-route-to-stream-not-working/20580 "2021-07-27T11:57:47Z")

</div>

Hi Community, I tried to use a pipeline to route/duplicate messages from one stream to a second stream. But nothing is routed. I see that the pipeline is processing messages but the target stream keeps empty. This is …

---

## [Best practice in ingesting logs](https://community.graylog.org/t/best-practice-in-ingesting-logs/20490)

<div class="topic-metadata">

**Author:** [@einsibjani](https://community.graylog.org/u/einsibjani)\
**Replies:** 3\
**Last updated:** [July 13, 2021, 2:40am UTC](https://community.graylog.org/t/best-practice-in-ingesting-logs/20490 "2021-07-13T02:40:44Z")

</div>

We’ve started moving our logs, mostly syslog to graylog. It’s working great, and we want to take it further and add more structure to our log data. Most of it is syslog, where we’re just shipping everything to graylog u…

---

## [Messages do not get through a pipeline - How to debug?](https://community.graylog.org/t/messages-do-not-get-through-a-pipeline-how-to-debug/20131)

<div class="topic-metadata">

**Author:** [@lukas.pavljuk](https://community.graylog.org/u/lukas.pavljuk)\
**Replies:** 7\
**Last updated:** [June 18, 2021, 11:01am UTC](https://community.graylog.org/t/messages-do-not-get-through-a-pipeline-how-to-debug/20131 "2021-06-18T11:01:49Z")

</div>

Hello, I had to modify an input from TCP Syslog to UDP Syslog (As one of our apps we want to use to send messages from into Graylog does not support TCP Syslog), but after removing the old input, creating a new one and …

---

## [Stream Rule Creation](https://community.graylog.org/t/stream-rule-creation/19354)

<div class="topic-metadata">

**Author:** [@miek](https://community.graylog.org/u/miek)\
**Replies:** 4\
**Last updated:** [April 2, 2021, 3:33pm UTC](https://community.graylog.org/t/stream-rule-creation/19354 "2021-04-02T15:33:05Z")

</div>

I have a simple case here. I want a specific log event to be added to my Stream. The messages exist and I can use search query in All Messages and it pulls up fine. I’m having a difficult time getting it to pipe into my …

---

## [Message clone plus route\_to\_stream in pipeline processor](https://community.graylog.org/t/message-clone-plus-route-to-stream-in-pipeline-processor/18983)

<div class="topic-metadata">

**Author:** [@riskersen](https://community.graylog.org/u/riskersen)\
**Replies:** 8\
**Last updated:** [March 4, 2021, 9:07pm UTC](https://community.graylog.org/t/message-clone-plus-route-to-stream-in-pipeline-processor/18983 "2021-03-04T21:07:20Z")

</div>

Dears, I’m trying to setup a separate stream with less information for a specific technical api user. rule “clone\_message\_to\_reroute\_stream\_C2S\_C2Svp” when has\_field(“service”) && contains(to\_string($message.service…

---

## [FYE: Tracking Windows Logon Type and Logon Errors With Graylog tables](https://community.graylog.org/t/fye-tracking-windows-logon-type-and-logon-errors-with-graylog-tables/18568)

<div class="topic-metadata">

**Author:** [@tmacgbay](https://community.graylog.org/u/tmacgbay)\
**Replies:** 7\
**Last updated:** [February 18, 2021, 11:11pm UTC](https://community.graylog.org/t/fye-tracking-windows-logon-type-and-logon-errors-with-graylog-tables/18568 "2021-02-18T23:11:49Z")

</div>

I had mentioned in a previous post we use Graylog tables to give more detail for tracking windows password failures. We including information on the type of logon that failed (Interactive, Network, Batch etc.) as well a…

---

## [Piping Interesting Events using chain of streams](https://community.graylog.org/t/piping-interesting-events-using-chain-of-streams/18648)

<div class="topic-metadata">

**Author:** [@Hari](https://community.graylog.org/u/Hari)\
**Replies:** 2\
**Last updated:** [February 9, 2021, 5:56pm UTC](https://community.graylog.org/t/piping-interesting-events-using-chain-of-streams/18648 "2021-02-09T17:56:13Z")

</div>

How can we achieve to pipe the interesting events that are stored in a different dedicated stream using the stream rules . Please be noted that the matches are removed from the default ( all messsages ) stream . Thank…

---

## [Please help me parse this message](https://community.graylog.org/t/please-help-me-parse-this-message/18639)

<div class="topic-metadata">

**Author:** [@poisedforflight](https://community.graylog.org/u/poisedforflight)\
**Replies:** 3\
**Last updated:** [February 2, 2021, 8:14pm UTC](https://community.graylog.org/t/please-help-me-parse-this-message/18639 "2021-02-02T20:14:15Z")

</div>

I am trying to work on Windows Logon Event Failures and have a message I need to break up into fields but I’m stumped as how to do so. I am not sure if I need to build a pipeline or an extractor. I do know that I’ll ev…

---

## [Graylog 4 - pipeline regex causes lost messages?](https://community.graylog.org/t/graylog-4-pipeline-regex-causes-lost-messages/18493)

<div class="topic-metadata">

**Author:** [@florianoverkamp](https://community.graylog.org/u/florianoverkamp)\
**Replies:** 5\
**Last updated:** [January 18, 2021, 8:39pm UTC](https://community.graylog.org/t/graylog-4-pipeline-regex-causes-lost-messages/18493 "2021-01-18T20:39:51Z")

</div>

Hi, I’m pretty new to this pipeline thing but I’m seeing something that makes no sense to me, and I’d appreciate a little feedback. Problem description: TL;DR: A pipeline that enriches exim4 loglines matches rules and…

---

## [Cloned message issue](https://community.graylog.org/t/cloned-message-issue/17821)

<div class="topic-metadata">

**Author:** [@gianluca-valentini](https://community.graylog.org/u/gianluca-valentini)\
**Replies:** 4\
**Last updated:** [November 13, 2020, 3:21pm UTC](https://community.graylog.org/t/cloned-message-issue/17821 "2020-11-13T15:21:14Z")

</div>

Hi, I added a cloned\_message() function in my first pipeline step and the message does not is visible on graylog stream. When I remove that cloning, then the message arrives and is visible on Stream1 I need to route t…

---

## [Routing Graylog Events into Another stream](https://community.graylog.org/t/routing-graylog-events-into-another-stream/17763)

<div class="topic-metadata">

**Author:** [@sunicod](https://community.graylog.org/u/sunicod)\
**Replies:** 2\
**Last updated:** [November 5, 2020, 8:00pm UTC](https://community.graylog.org/t/routing-graylog-events-into-another-stream/17763 "2020-11-05T20:00:11Z")

</div>

I understand there is a stream called All events. I would like to route all graylog events that are alerts into another stream. I have tried creating the following pipeline rule but no messages have been coming through. …

---

## [Message and cloned message in rules on Stage pipeline](https://community.graylog.org/t/message-and-cloned-message-in-rules-on-stage-pipeline/17761)

<div class="topic-metadata">

**Author:** [@gianluca-valentini](https://community.graylog.org/u/gianluca-valentini)\
**Replies:** 0\
**Last updated:** [November 5, 2020, 4:06pm UTC](https://community.graylog.org/t/message-and-cloned-message-in-rules-on-stage-pipeline/17761 "2020-11-05T16:06:30Z")

</div>

Hi, I need a clarification/help on Rule on Pipeline stages. This is my scenario and I try to explain the message lifecycle with you: Input Gelf Stream1(with rule to address message that comes from Input Gelf) …

[Next page](https://community.graylog.org/tag/route-to-streampl/11.md?match_all_tags=true&page=1&tags%5B%5D=route-to-streampl)
