Hi, I am using a collector to read from a logfile. All is working perfectly. The events as received into graylog look like:
eventtime: 2018-07-01T16:25:08Z, account_id: 123456, email: email@example.com, ip_addr: 22.214.171.124 etc
Right now this all just appears in the ‘message’ field. I plan on using a pipeline rather than an extractor to separate out the fields (as not all incoming logs to that input will necessarily be in the same format).
Is there an easy way using pipeline rules to break the contents of the message out into separate fields?
Graylog version 2.4.5