I am using graylog 2.4.1 and i sucesfully deployed collectors, streams and inputs.
But i am not being able to connect an extractor to a input/stream.
Under the syslog UDP input i added an extractor that speficifc tries to matches all messages, it loads a example message and it got extracted (it shows up the field that are being extracted) but no message is extracted.
All the messages formed in the same way in the same input, doesnt get extracted.
And sorry, in the documentation it says how to create an extractor, but not what to do next:
- Add to a pipeline?
- Add to a rule?
- Dance around it in circles