12. Graylog 3.0 Grok Patterns, Extractors and Pipelines || part 1

แชร์
ฝัง
  • เผยแพร่เมื่อ 29 ก.ย. 2024
  • www.facebook.c...
    / bitsbytehard
    --------------------------------------------------------

ความคิดเห็น • 32

  • @dotcaodin
    @dotcaodin 5 ปีที่แล้ว

    Great channel. Thanks for the job.

  • @garchafpv
    @garchafpv 3 ปีที่แล้ว +2

    Awesome vid man. I have a sonicwall. I'm wondering what's the best way to extract that. I have the data flowing to graylog but I can't seem to find any decent examples for sonicwall. The only 2 things in the marketplace are years old and are using the split and index method which I don't think will work for me because the index can change depending on the type of message

    • @BitsByteHard
      @BitsByteHard  3 ปีที่แล้ว

      try to watch all the videos i did for grok patterns, do practice and you'll make it for sure

  • @brianlogan4740
    @brianlogan4740 5 ปีที่แล้ว +2

    I appreciate the video but I had to really turn every volume setting I had all the way up to hear you okay.

    • @BitsByteHard
      @BitsByteHard  5 ปีที่แล้ว

      had some issues in the past with the sound...
      how are the latest videos regarding sound?

  • @Danielo515
    @Danielo515 3 ปีที่แล้ว

    how is pipeline rules different than telling the rule to only run if the message contains certain string?

    • @BitsByteHard
      @BitsByteHard  3 ปีที่แล้ว

      the pipeline can contain multiple rules, but the rule itself is part of a pipeline. and once the pipelines are created and applied to a certain stream they will run no matter what. it doesn't matter if the message will match or not, they will be run for every message that goes in that stream.

    • @Danielo515
      @Danielo515 3 ปีที่แล้ว

      @@BitsByteHard thanks for the answer. If pipelines can be attached to one specific stream that may be interesting. Extractors are only applied to inputs, so they have the potential to run much more times than needed compared to an stream, which is usually more narrowed to certain messages or server. Thanks

  • @jovanjanevski3747
    @jovanjanevski3747 4 ปีที่แล้ว +1

    I can't hear louder...

  • @dummyaccount9578
    @dummyaccount9578 2 ปีที่แล้ว

    Hi there, on your messages. How did you set your source as Ip address mine it shows the Host/PC name btw i'm using UDP Gelf as an input

  • @jipjohnusa4094
    @jipjohnusa4094 5 ปีที่แล้ว +1

    I tried to filter our messages with Graylog for the past 7 months and got nowhere. Finally, I found your video. Excellent information! Thank you!

    • @BitsByteHard
      @BitsByteHard  5 ปีที่แล้ว

      glad you liked it
      you might wanna check the 2nd part which i did for the pipelines ;) th-cam.com/video/pb25AW-CEzQ/w-d-xo.html

    • @BitsByteHard
      @BitsByteHard  5 ปีที่แล้ว

      thanks. hope you'll enjoy grayloging :D

  • @MohammadAli-xs3px
    @MohammadAli-xs3px 3 ปีที่แล้ว +1

    what is the % sign in grok pattern?

    • @BitsByteHard
      @BitsByteHard  3 ปีที่แล้ว

      logz.io/blog/logstash-grok/

  • @alljunk5129
    @alljunk5129 6 หลายเดือนก่อน

    Very helpful to get a grasp of Graylog extractors!

  • @ladejebimodupe1174
    @ladejebimodupe1174 4 ปีที่แล้ว

    Appreciate the video. Its working fine but only for new streams coming in but old streams are not applied, any help with be appreciated. Thanks

    • @BitsByteHard
      @BitsByteHard  4 ปีที่แล้ว

      the grok pattenrs extactors or the rules in the pipeline apply only to those specific patterns that they are created for, if your streams have different patterns then it won't work.
      if this doesn't apply there you really have a issue with graylog and i suggest you to upgrade to the latest version or open a topic with the graylog community, maybe they have a bug in it

  • @guesmihouyem7387
    @guesmihouyem7387 5 ปีที่แล้ว

    hi please can you help me i have different time and i don't receive log in real time ? how i can configure it

    • @BitsByteHard
      @BitsByteHard  5 ปีที่แล้ว

      your company should have an NTP servers to sync your servers with it, if not you can use a public one www.ntppool.org/en/use.html

  • @yannisboukari2569
    @yannisboukari2569 4 ปีที่แล้ว

    Hello man, first of all thanks for sharing your knowledge. I would like to know how did u get the left side bar who allow you to "Search result". I missed it on my installation. Thanks for the answer and "Bonjour" from France!

    • @BitsByteHard
      @BitsByteHard  4 ปีที่แล้ว

      Hi Yannis, the search bar might be different from one graylog version to another, in this one i'm using graylog 3.0.
      i would appreciate if you could be more specific indicating the minute and second.

    • @yannisboukari2569
      @yannisboukari2569 4 ปีที่แล้ว

      @@BitsByteHard Thanks for your reply. I'm using graylog 3.2 and i was meaning the left side bar on your screen at 0:02. Because from it you can select a specific field and click on "quick values". And I wanted to do this action. In the night i resolve my issue. The problem was : there is no problem. The extractors works well but only on new data incoming and not on all date already stored. So when i receive more data i realise that it work well. Thanks you again for your reply and sorry for my bad english. I appreciate a lot your entire work.

    • @BitsByteHard
      @BitsByteHard  4 ปีที่แล้ว +1

      @@yannisboukari2569 in the 3.2 version you can click on Search -> expand the search with the arrow -> fields
      for more info you can check the video i made about version 3.2 th-cam.com/video/uo5mDD8AUNc/w-d-xo.html
      minute 9:21