RE: [graylog2] Need assistance on building an alert.

2016-08-19 Thread Tom Vile
Here I am over thinking the issue. I will talk with the networking guys to go that route as it makes sense and keeps the processing down on my server. We use Cisco gear and have worked on them before and have done something similar in the past. I guess since I don't control the networking equipm

RE: [graylog2] Need assistance on building an alert.

2016-08-19 Thread STARNES, CURTIS
Tom, I didn’t see where you specified the firewall/routers but I have an ACL in our Cisco router that checks outbound traffic and if any traffic matches an ACL rule it is set to log. This router logging is sent to our Graylog2 collector via syslog messages to the specified IP/port combination. T

[graylog2] Need assistance on building an alert.

2016-08-19 Thread Tom Vile
I have been tasked with building out a Graylog2 cluster solution at my company and it has been going very well but need some help with the best way to handle a rather complex alert. We have roughly1500 Windows computers with 4 at roughly 400 locations on their own private networks. They are loc

Re: [graylog2] Syslog severity mapper decorator

2016-08-19 Thread Jan Doberstein
Hej Marcus That whats what I hoped for, but to me it looks like nothing has changed at  all. Everything is like it was with 2.0 and/or 2.1beta2. I must be kind of  too blind to see ;)  >From my understanding I could still search for something like:  level:<4 AND message:foo  But I would expect t

Re: [graylog2] Starting graylog2-server redirecting stderr to stdout

2016-08-19 Thread Jan Doberstein
Hej Charmant, I can have a web link, who show me why to install a latest version of graylog2 step by step on ubuntu 14.04 amd64 or more ? Or a web link to download a vmdk (vm ware machine who run graylog2? Help me please!! did you tried one of the described installation in the graylog documenta

Re: [graylog2] Speed up the Web Interface

2016-08-19 Thread Dennis Oelkers
Hey Philipp, which part of it is slow? Kr, D. > On 19.08.2016, at 13:52, Philipp J. wrote: > > We use 2.0.3 > > Am Donnerstag, 18. August 2016 10:15:32 UTC+2 schrieb Dennis Oelkers: > Hey Philipp, > > which Graylog version are you using? Starting with 2.0, the web interface is > a

Re: [graylog2] Speed up the Web Interface

2016-08-19 Thread Philipp J.
We use 2.0.3 Am Donnerstag, 18. August 2016 10:15:32 UTC+2 schrieb Dennis Oelkers: > > Hey Philipp, > > which Graylog version are you using? Starting with 2.0, the web interface > is a client side application, which should consume much less resources on > the server, so upgrading might help you