Is there a garbage collector service, when using the pm_buffer to disk, so that the buffer file on disk is emptied? If yes, how often is this run, and can it be configured?


AskedOctober 26, 2015 - 12:21pm

Is there a way to aggregate multiple messages into one email?

we need to separate and aggregate events per IP address during a period of time, such that, a single email is sent conteining multiple messages where the same IP is present, is this something that can be done with pm_evcorr?

i hace tried and not yet able to get this functionality, if possible pls provide a quick example.


AskedOctober 21, 2015 - 8:43pm

ASSERTION FAILED at line 33 in xm_gelf.c/xm_gelf_writer_udp()

hi , 2 days ago i started getting this error :

ERROR ### ASSERTION FAILED at line 33 in xm_gelf.c/xm_gelf_writer_udp(): "deflateInit(&strm, Z_DEFAULT_COMPRESSION) == Z_OK" ###
INFO reconnecting in 1 seconds


anu idea ? tks .

AskedOctober 20, 2015 - 4:16pm

CSV-input: converting specific field(s) to lowercase

Dear community,

I'm currently working on parsing MS Exchange logs and sending them via GELF to my graylog instance.

I'd like to convert the sender- and recipient-address field to lowercase. Sounds pretty easy, in fact, I need help :(

my current config looks like this (below). Any help is appreciated.

I've tried to work with "Exec       $sender-address = lc($sender-address);" within the input as well as Output backet - neither did work.

AskedOctober 15, 2015 - 6:40pm