hi, i use graylog to check http traffic from exchange. On exchange http log i have this field called UserAgent that contain value like this:
Microsoft Office/16.0 (Windows NT 6.1; Microsoft Outlook 16.0.4549; Pro)
How i can create a rule to spilt this message into two field like OS and program? And i can create a lookup table for Operating system like Windows NT 6.1 -> Windows 7?