Hi, I created a few Grok pattern extractors for Zyxel log entries.
Input is Standart Suslog input
Source string is:
<141>May 23 07:33:48 zywall-110 CEF:0|ZyXEL|ZyWALL 110|4.20(AAAA.2)|0|Access Control|5|src=172.19.5.40 dst=126.96.36.199 spt=49536 dpt=443 msg=priority:36, from LAN1 to ANY, TCP, service others, ACCEPT proto=6 app=others
I need to extract values, for example:
And it obviously works, output is:
But doesn’t appears as fields in Search
What I do wrong?
And another Question: Does Graylog support multiple inputs on the same Network port?