11. Stages
“Stages are groups of conditions and actions which
need to run in order. [...] Stages provide the
necessary control flow to decide whether or not to
run the remaining stages in a pipeline.”
21. Lookup Tables - Examples
➥ Correlate VM to Hypervisor
➥ Correlate switches and VLANs from CMDB
➥ Translate log “codes” to human readable
meaning
➥ Add Point of Contact from CMDB
29. Acknowledgements
Eric Capuano
➥ @eric_capuano
➥ Taught me all the things
Jan Doberstein
➥ @jalogisch
➥ Helped me understand
Graylog at a deeper level
Lennart Koopmann
➥ @_lennart
➥ Answered a lot of questions
and helped me solve a lot of
problems
BrakeSec #siem-logging
➥ @brakesec