So I have some vpn logs like :
openvpn: timmy-vpn/192.168.8.11:52533 MULTI_sva: pool returned IPv4=192.168.90.5, IPv6=(Not enabled)
openvpn: tammy-vpn/192.168.8.12:51667 MULTI_sva: pool returned IPv4=192.168.90.6, IPv6=(Not enabled)
openvpn: tommy-vpn/192.168.8.13:55875 MULTI_sva: pool returned IPv4=192.168.90.7, IPv6=(Not enabled)
I would like to generate a field populated with the username AND the IPv4. Like
I started down the Grok road, and got something like this to match:
It works on this Grok tester :
I created the Grok in the place you create them in Graylog.
But in the interface to create an extractor, this Grok doesn’t seem to match anything.
And I’m starting to think the Grok thing might not be what I’m looking for.
Is there a way to grab arbitrary parts of a text log message an join them together to a field?