Aggregates Plugin

Plugin 2.2.4

Aggregates plugin for Graylog



15 Jun 06:56

Last Push

15 Jun 06:46

cvtienhoven 7 months ago

For any issues, please head over to GitHub and file an issue when needed, as I don't check the comments on the marketplace very often. Cheers!

safecyn 11 months ago

Is this plugin up to date with Graylog 2.4? For some reason when I installed it, the aggregates tab shows up, but not even the admin user has permissions to edit schedules, not even the pre-existing sample ones.

shchbo about 1 year ago

when i try to send an alert with out the option of "in report" it does not work. it sends the mail only when to check box is checked. graylog 2.3.0

mhocso over 1 year ago

Nice plugin! Is it possible to add the $field value to the alert message? So if source is used for tracnig failed logins for example can the alert contain the source that matched (ex Right now it does alert but i need to fill the IP for callback to the website.

Kakuden over 1 year ago

@cvtienhoven I installed 2.1.1 and could create a aggregates rule.

cvtienhoven over 1 year ago

@Kakuden: this was a bug, I released a fix for this today (version 2.1.1). Should be available on Marketplace soon, or else on the Github page:

Kakuden over 1 year ago

I installed this plugin(2.1.0) on virtual appliance(2.3.1-3).
When I tried to create Aggregate Rule, the following error message appeared and failed to create rule.

Could not create rule
Creating rule failed with status: cannot PUT http://:9000/api/plugins/org.graylog.plugins.aggregates/rules (500)

Are there any ways to fix this?

elvioorg over 1 year ago

It's a great plugin, but I've a problem to use with HTTP Alert Notification.
I have configured a notification with HTTP ALARM CALLBACK in aggregate plugin, but I get the HTTP POST messages empty as reported here below:

[function] => graylog
Does anyone know how to configure (custom) an http callback? THANK YOU
All email callbacks work perfectly.

cvtienhoven over 1 year ago

In the query you can use AND, but it's not possible (yet) to combine two fields. You'd have to introduce a field yourself in which you concatenate the two fields for instance, and use that new field in the plugin.

Harris108 over 1 year ago

Nice plugin. Just want to know if this plugin can be used to make a query of two fields together with an AND ?
for Example
Query : Root AND
Filed : user_type AND user_agent


cannojr over 1 year ago

Excellent work on this plugin.

berekese over 1 year ago

Hi, I'm using Graylog v2.3.0-alpha.3+c795033 but when I put that plugin on his directory and I restart the graylog-server doesn't start. I can't see any logs error, this is last lines:
2017-06-08T09:37:30.212+02:00 INFO [CmdLineTool] Loaded plugin: Aggregates 1.0.1 [org.graylog.plugins.aggregates.AggregatesPlugin]
2017-06-08T09:37:30.214+02:00 INFO [CmdLineTool] Loaded plugin: Elastic Beats Input 2.3.0-alpha.3 []
2017-06-08T09:37:30.215+02:00 INFO [CmdLineTool] Loaded plugin: Collector 2.3.0-alpha.3 [org.graylog.plugins.collector.CollectorPlugin]
2017-06-08T09:37:30.216+02:00 INFO [CmdLineTool] Loaded plugin: Enterprise Integration Plugin 2.3.0-alpha.3 [org.graylog.plugins.enterprise_integration.EnterpriseIntegrationPlugin]
2017-06-08T09:37:30.216+02:00 INFO [CmdLineTool] Loaded plugin: MapWidgetPlugin 2.3.0-alpha.3 []
2017-06-08T09:37:30.217+02:00 INFO [CmdLineTool] Loaded plugin: NetFlowPlugin 0.1.0 [org.graylog.plugins.netflow.NetFlowPlugin]
2017-06-08T09:37:30.224+02:00 INFO [CmdLineTool] Loaded plugin: Pipeline Processor Plugin 2.3.0-alpha.3 [org.graylog.plugins.pipelineprocessor.ProcessorPlugin]
2017-06-08T09:37:30.225+02:00 INFO [CmdLineTool] Loaded plugin: Anonymous Usage Statistics 2.3.0-alpha.3 [org.graylog.plugins.usagestatistics.UsageStatsPlugin]
2017-06-08T09:37:30.225+02:00 INFO [CmdLineTool] Loaded plugin: SnmpPlugin 0.3.0 [org.graylog.snmp.SnmpPlugin]
2017-06-08T09:37:30.444+02:00 INFO [CmdLineTool] Running with JVM arguments: -Xms1g -Xmx1g -XX:NewRatio=1 -XX:+ResizeTLAB -XX:+UseConcMarkSweepGC -XX:+CMSConcurrentMTEnabled -XX:+CMSClassUnloadingEnabled -XX:+UseParNewGC -XX:-OmitStackT
raceInFastThrow -Dlog4j.configurationFile=file:///etc/graylog/server/log4j2.xml -Djava.library.path=/usr/share/graylog-server/lib/sigar -Dgraylog2.installation_source=deb
2017-06-08T09:37:30.646+02:00 INFO [Version] HV000001: Hibernate Validator null

Any idea? Thanks.

vsegdacocacola over 1 year ago

Great job! +1 to have alerts in Graylog itself

cvtienhoven almost 2 years ago

@BlackPearl01: Scheduling of reports is now included (as of version 1.0.0).

BlackPearl01 almost 2 years ago


First, thank you for your plugin for GrayLog! It's useful and help me to create some alerts in GrayLog.

The PDF report are very useful too! But as you had write, for the moment, the configuration of intervals, schedules etc. for reports is not possible yet.

Have you an idea of the date when you can develop and include this feature in your plugin?

Thank you again,

Nemesis741 over 2 years ago

Nice Plugin. It would be cool if the alarms of these agregates could be counted and added to a dashboard.

We sometimes have duplicated requests on some of our webservers, so it would be nice to add a counter like "There were 15 duplicates in the last hour" to our dashboards.

aarvee11 over 2 years ago

Loved the plugin. Awesome work bro!

