Connecting an extractor to a input

(Psy Skeletor) #1


I am using graylog 2.4.1 and i sucesfully deployed collectors, streams and inputs.
But i am not being able to connect an extractor to a input/stream.

Under the syslog UDP input i added an extractor that speficifc tries to matches all messages, it loads a example message and it got extracted (it shows up the field that are being extracted) but no message is extracted.

All the messages formed in the same way in the same input, doesnt get extracted.
And sorry, in the documentation it says how to create an extractor, but not what to do next:

  • Add to a pipeline?
  • Add to a rule?
  • Dance around it in circles :slight_smile:

(Jan Doberstein) #2

the extractor is always bound to the input - period.

It does not need any further actions after you created and saved the extractor. If this does not work, the extractor is not working.

(Psy Skeletor) #3

Hi Jan.
Thanks for the reply.

I will try to upload an image of the extractor’s panel, it seems it is in fact processing messages but not piping them out.

(Psy Skeletor) #4

And the grok is applied to the stream which is being piped from the input

(Jan Doberstein) #5

Your full_message does not match the Grok pattern you try to use.

(Psy Skeletor) #6

another screenshot, it returns me the info as i requested :thinking:

(Jan Doberstein) #7

You discovered that the system is not consistent.

The GROK Pattern need to match the complete field - in the processing. But the try does also match partly.
Please open an issue for that:

(system) #8

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.