Graylog query details
This commit is contained in:
@@ -105,6 +105,11 @@ Graylog event is not learned repeatedly. Related anomalies, profile deviations,
|
||||
and multi-stream correlations are grouped into investigation incidents with a
|
||||
compact evidence timeline.
|
||||
|
||||
Timeline and related-activity rows include copyable Graylog query details built
|
||||
from normalized source, destination, action, and DNS fields. These are query
|
||||
details rather than hard-coded web links, so they work with MCP and with Graylog
|
||||
deployments behind different URLs or reverse proxies.
|
||||
|
||||
Incident lifecycle state is stored locally in `state/signalscope-incidents.json`.
|
||||
Use the dashboard incident actions to acknowledge, resolve, or reopen an incident
|
||||
and attach a note. The state is keyed to a stable incident fingerprint so it can
|
||||
|
||||
Reference in New Issue
Block a user