Graylog query details

This commit is contained in:
larssand
2026-06-29 19:26:16 +02:00
parent 4a85e53869
commit 16b5bbdd63
8 changed files with 103 additions and 20 deletions

View File

@@ -105,6 +105,11 @@ Graylog event is not learned repeatedly. Related anomalies, profile deviations,
and multi-stream correlations are grouped into investigation incidents with a
compact evidence timeline.
Timeline and related-activity rows include copyable Graylog query details built
from normalized source, destination, action, and DNS fields. These are query
details rather than hard-coded web links, so they work with MCP and with Graylog
deployments behind different URLs or reverse proxies.
Incident lifecycle state is stored locally in `state/signalscope-incidents.json`.
Use the dashboard incident actions to acknowledge, resolve, or reopen an incident
and attach a note. The state is keyed to a stable incident fingerprint so it can