Graylog2 / Graylog2/graylog2-server

New event's tag/highlight in Table by long time range - Silent Attack

Open
#9,954 0 comments 0 reactions 0 assignees View on GitHub
feature Low Prio
Dominant language
Java
Stars
8.1k
Forks
1.1k
Avg merge
1d 20h
Merged PRs (30d)
217

Description

## What?

Think I have a Table with Events on Last Day. I want to set a field->true OR Highlight the Event Line when that event is New(based on a query from 30 days OR 15 days OR all messages)

## Why?

In cyber attacks uncommon events or events that occurs less or events that never happen before, that is more sophisticated attacks or silent attacks. Then with something like this I think will be really helpful.

## Your Environment

* Graylog Version: 4.0.1
* Elasticsearch Version: 79.3
* MongoDB Version: 4.2
* Operating System: FreeBSD 12.1

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.