airbus-cyber / graylog-plugin-alert-wizard

Alert Wizard plugin for Graylog to manage the alert rules
Other
46 stars 7 forks source link

Ability to create rules with a Graylog query #124

Open frantz45 opened 9 months ago

frantz45 commented 9 months ago

When we started this plugin the only possibility to filter logs in an Event Definition were the Streams. But now Graylog can also use a query.

image

So when creating a rule with the Wizard we could also be able to set a query in addition to optionnaly use Streams.

c8y3 commented 9 months ago