Hi,
I have a 'complex' (for me at least) question. What I want to achieve is the following:
1)
index=abc msg="*firewall off*" |table _time,hostname,msg
>this will give me, for example: hostname = machine1 msg = "the firewall has been turned off" >> I want to be triggered if someone turns off the firewall
Now, the actual issue I have now is the following: A few seconds before this event, I might get a "system update event" that updates the firewall (agent update), which is OK, and I do NOT want this event. I would need to combine both queries into 1 alert. 2)
index=abc hostname=machine1 NOT msg="*system updated*"
I want to see the result of 1, but only if it was not preceeded by 2.
I hope this makes sense.
... View more