How to filter repetitive events

In case of DOS attack on a device, there would be a surge of logs in a very short time and all the events look simillar with change in one or two parameters source port/destination port/source ip/destination ip. In such case, can we filter such repeatitive logs in NXLOG agent? If yes, How to do that? I tried pm_norepeat but it didnt help. Any other alternate options?



AskedOctober 6, 2017 - 5:46pm

Possibility of Global Tags for all Inputs

What I'm trying to achive is to have a few Values globaly defined and the should be automatically added to all inputs.
Ie the same thing as Global Tags in Telegraf

Today I first use a define statement in the global part of NXLog.conf

Define Company Acme 


For each input I define i have to add a Exec line

Exec $Company = '%Company%';

AskedSeptember 29, 2017 - 1:32pm