Assistance with extractors

Just an fyi, My last lesson on pipelines was from here.

Something like this will work

rule "Regex multiple fields"
when
  has_field("message")
then

  let robin = regex("mode=(\\S+).*src_ip=(\\S+).*src_port=(\\S+)", to_string($message.message));

  set_field("mode",      robin["1"]);
  set_field("src_ip",    robin["2"]);
  set_field("src_port",  robin["3"]);  

end
2 Likes