Under Construction, excuse the mess!
chateaulav / pihole Goto Github PK
View Code? Open in Web Editor NEWContent Pack for piHole with Graylog
License: GNU General Public License v3.0
Content Pack for piHole with Graylog
License: GNU General Public License v3.0
I am having problems with the pipelines not processing the messages... I believe it has to do with the format of the messages that I am forwarding from pihole... my messages are currently forwarding in the following format (with rsyslog):
full_message:
<190>Oct 21 13:08:15 pi-1 pihole Oct 21 13:08:15 dnsmasq[581]: query[A] example.google.com from XXX.XXX.XXX.XXX
However when I look at the screen shot from the original post (https://jalogisch.de/2017/der-eigene-dns-resolver-zuhause/) the format of the message is different and I am wondering if this is causing a problem with the pipeline processing...
I don't want to start tweaking all the grok patterns if its the message format that is wrong. could you share the rsyslog template / fowarding conf that you are using to confirm this or not.
I am currently using the following for rsyslog forwarding...
. action(type="omfwd" target="xxx.xxx.xxx.xxx" port="1514" protocol="udp"
action.resumeRetryCount="100"
queue.type="linkedList" queue.size="10000")
module(load="imfile" PollingInterval="10")
input(type="imfile" File="/var/log/pihole.log"
StateFile="/var/run/pihole.log.state"
Tag="pihole"
Severity="info"
Facility="local7")
I'm running Graylog 4.1 and PiHole 5.3.1 and latest syslog-ng.
Seems to me most things are broken based on syslog-ng adding fields now and pinhole log formats have changed slightly so the grok patterns don't work (so most other stuff breaks as the pipelines don't function.
Is this just me?
Do you have plans to update this before I spend hours fixing grok patterns?
I'm new to Graylog so be patient as I learn. I installed Graylog last week and have successfully ingested log data from Windows, Linux and my Firewall. I downloaded and installed this Content Pack and without issue began ingesting data... but nothing on the Dashboard. I'm running Graylog 4.0.7 and PiHole 5.3.1 Is there something I'm missing in the Extractor or Dashboard that I should have edited? Or should it have worked "out of the box?"
A declarative, efficient, and flexible JavaScript library for building user interfaces.
๐ Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. ๐๐๐
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google โค๏ธ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.