Graylog2 / Graylog2/graylog2-server
New event's tag/highlight in Table by long time range - Silent Attack
Open
feature
Low Prio
- Dominant language
- Java
- Stars
- 8.1k
- Forks
- 1.1k
- Avg merge
- 1d 20h
- Merged PRs (30d)
- 217
Description
## What?
Think I have a Table with Events on Last Day. I want to set a field->true OR Highlight the Event Line when that event is New(based on a query from 30 days OR 15 days OR all messages)
## Why?
In cyber attacks uncommon events or events that occurs less or events that never happen before, that is more sophisticated attacks or silent attacks. Then with something like this I think will be really helpful.
## Your Environment
* Graylog Version: 4.0.1
* Elasticsearch Version: 79.3
* MongoDB Version: 4.2
* Operating System: FreeBSD 12.1
Contributor guide
Assessment
This issue has not been assessed yet.