Graylog2 / Graylog2/graylog2-server

Event Definition New Feature: Add a bulk edit feature

Open
#21,427 5 comments 0 reactions 1 assignee Claimed by @Emy-01 View on GitHub
feature triaged
Dominant language
Java
Stars
8.1k
Forks
1.1k
Avg merge
1d 20h
Merged PRs (30d)
217

Description

## What?

A bulk editing feature for Event Definitions would reduce the needed time create useful alerts. Currently, each Event Definition has to be edited manually.

## Why?

With the introduction of SIGMA rules and curated alerts, a customer will have hundreds of Event Definitions. If a customer or the developer team like SecCon wants to include an important custom field like user_name or an IP field, the user or developer has to create the keys in each Event Definition.

A bulk edit function of the fields tab would reduce the time to modify all event definitions from many hours to a few minutes.

Maybe it also makes sense to have this feature for Notifications, adding Streams and Stream Categories, modify execution times (if it does not already exist.)

![Image](https://github.com/user-attachments/assets/db0c8637-f58a-4810-947d-3e3b13e00854)

## Your Environment

* Graylog Version: 6.2
* OpenSearch Version:
* MongoDB Version:
* Operating System:
* Browser version:

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.