# Extractor fields not appearing when simulating pipeline

**URL:** <https://community.graylog.org/t/extractor-fields-not-appearing-when-simulating-pipeline/14871>\
**Category:** Graylog Central (peer support)\
**Tags:** pipeline-rules, debuggingpl\
**Created:** [April 7, 2020, 3:33pm UTC](https://community.graylog.org/t/extractor-fields-not-appearing-when-simulating-pipeline/14871 "2020-04-07T15:33:06Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![ylmcc](https://avatars.discourse-cdn.com/v4/letter/y/bbce88/32.png) [@ylmcc](https://community.graylog.org/u/ylmcc)\
**Post date:** [April 7, 2020, 3:33pm UTC](https://community.graylog.org/t/extractor-fields-not-appearing-when-simulating-pipeline/14871/1 "2020-04-07T15:33:06Z")

</div>

Hi Guys,

I am quite puzzled with using pipelines, I have created an udp raw input with extractors which sends all messages into “All Messages” with the fields from my extractors added.

When it comes to simulating the pipeline I am unable to see my extractors working on the simulated message. Under “Message Input (optional)” I have selected the input which the message would appear on for codec configuration I have selected “Raw String” would this affect it?

The order my messages are processed are as follows:

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/9/9c05a1bd50325ade3a41397161f7687d53becbdb.png)

Thanks

Edit: Current version of Graylog 3.2.4

---

<div class="post-metadata">

**Author:** ![shoothub](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/shoothub/32/6412_2.png) [@shoothub](https://community.graylog.org/u/shoothub)\
**Post date:** [April 7, 2020, 4:11pm UTC](https://community.graylog.org/t/extractor-fields-not-appearing-when-simulating-pipeline/14871/2 "2020-04-07T16:11:47Z")

</div>

Pipeline simulator can’t process all pipeline rules. I prefer to use debug pipeline function, to check if it works.  
[https://docs.graylog.org/en/3.2/pages/pipelines/functions.html#debug](https://docs.graylog.org/en/3.2/pages/pipelines/functions.html#debug)

> let debug\_message = concat("Test message from ", to\_string($message.source));  
> debug(debug\_message);

After that check your server log in log file /var/log/graylog-server/server.log  
using for example tail from command line of graylog server:

> tail -f /var/log/graylog-server/server.log

---

<div class="post-metadata">

**Author:** ![ylmcc](https://avatars.discourse-cdn.com/v4/letter/y/bbce88/32.png) [@ylmcc](https://community.graylog.org/u/ylmcc)\
**Post date:** [April 7, 2020, 4:15pm UTC](https://community.graylog.org/t/extractor-fields-not-appearing-when-simulating-pipeline/14871/3 "2020-04-07T16:15:27Z")

</div>

I’ll give a go and see what happens. Thanks ! 🙂

---

<div class="post-metadata">

**Author:** ![andrenandes](https://avatars.discourse-cdn.com/v4/letter/a/bcef8e/32.png) [@andrenandes](https://community.graylog.org/u/andrenandes)\
**Post date:** [April 13, 2020, 2:23pm UTC](https://community.graylog.org/t/extractor-fields-not-appearing-when-simulating-pipeline/14871/4 "2020-04-13T14:23:07Z")

</div>

Good afternoon.

I am taking advantage of this recently opened thread to look for help, as I have a very similar issue.

I have a JSON message entering Graylog through a Raw/plaintext TCP input, with an associated extractor. This parses my json message just fine, including nested fields. Example: ![extractor](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/9/95341315e68ab36cef2e2b3f1f35b4fe88d50f09.png)

This goes into a stream called “Azure Devops”, which is correctly configured, I can see all the data in Graylog, including all the extracted fields. Example:  
 ![stream](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/c/c5fb53178fa108702852e5074153474e07c9b458.png)

However, I also need to create an additional field (timeToBuild), which is an operation between two fields (more specifically, I want to calculate time difference as epoch between 2 timestamps in the input json: timeToBuild = resource\_finishTime - resource\_startTime). So I created a Pipeline and a Rule, associated this rule to the pipeline, and connected the pipeline to my “Azure Devops” stream. Example:

 ![pipeline](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/8/86bb92cf81972b53304a1f1486ab0c0da44360da.png)  
 ![rule](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/b/b87e16351d9ced109801d7b1450f041a1b35f55d.png)

My “Message Processing Configuration” is also in the correct order, with “Message Filter Chain” before “Pipeline Processor”. Example:  
 ![configuration](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/2/2a76baae892dc881f32a5e89423d99cfbb4f0ea3.png)

However, when I try to simulate my pipeline (using my configured input, and the expected raw json message), the entire raw message is contined in the “message” field, as if my extractor didn’t work. Since everything is in a bulk inside the “message” field, my pipeline rule stage 0 condition fails to find any data and stops processing. As a result, my new “timeToBuild” field is not showing up in Graylog. Example:

 ![simulator config](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/8/8ae56ad649c574e610418c0684702745cfa3b5fd.png)  
 ![simulator](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/8/82513d7424c0ae1a29871b8b1d1eeee79119edd4.png)

I guess I am doing something wrong, but after reading a lot of documentation and forum posts I have no idea what. I greatly appreciate any help.

Thank you!

---

<div class="post-metadata">

**Author:** ![ylmcc](https://avatars.discourse-cdn.com/v4/letter/y/bbce88/32.png) [@ylmcc](https://community.graylog.org/u/ylmcc)\
**Post date:** [April 14, 2020, 11:00am UTC](https://community.graylog.org/t/extractor-fields-not-appearing-when-simulating-pipeline/14871/5 "2020-04-14T11:00:42Z")

</div>

This worked for me, I see somewhere it was not possible to drop the “message” field but could be removed in the future.

Thank you shoothub for the debug tip!

---

<div class="post-metadata">

**Author:** ![ylmcc](https://avatars.discourse-cdn.com/v4/letter/y/bbce88/32.png) [@ylmcc](https://community.graylog.org/u/ylmcc)\
**Post date:** [April 14, 2020, 11:03am UTC](https://community.graylog.org/t/extractor-fields-not-appearing-when-simulating-pipeline/14871/6 "2020-04-14T11:03:27Z")

</div>

Posting in a new thread would make this easier to read. However you should use `debug(variable_you_are_trying_to_view)` and as shoothub suggested

`````auto
tail -f /var/log/graylog-server/server.log````
`````

---

<div class="post-metadata">

**Author:** ![andrenandes](https://avatars.discourse-cdn.com/v4/letter/a/bcef8e/32.png) [@andrenandes](https://community.graylog.org/u/andrenandes)\
**Post date:** [April 20, 2020, 9:27am UTC](https://community.graylog.org/t/extractor-fields-not-appearing-when-simulating-pipeline/14871/7 "2020-04-20T09:27:57Z")

</div>

Good morning @ylmcc

Thank you for your reply.  
I will follow your advice and make a new post for this, as it’s probably better suited.

I have also added the debug message as for your suggestion, but so far it hasn’t yielded any useful messages yet (messages have arrived in the meanwhile, and show on Graylog, but my debug message didn’t show up in the server.log file).

Thank you.

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [April 28, 2020, 11:32am UTC](https://community.graylog.org/t/extractor-fields-not-appearing-when-simulating-pipeline/14871/8 "2020-04-28T11:32:02Z")

</div>

he all

you might need to know that the simulator need the message ingested as this comes in to graylog - so that all extractors and every can actually run on that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [May 12, 2020, 11:32am UTC](https://community.graylog.org/t/extractor-fields-not-appearing-when-simulating-pipeline/14871/9 "2020-05-12T11:32:04Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
