# Extractor for Wallix message

**URL:** <https://community.graylog.org/t/extractor-for-wallix-message/18751>\
**Category:** Graylog Central (peer support)\
**Created:** [February 10, 2021, 7:48am UTC](https://community.graylog.org/t/extractor-for-wallix-message/18751 "2021-02-10T07:48:32Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![cyrilvigreux](https://avatars.discourse-cdn.com/v4/letter/c/f475e1/32.png) [@cyrilvigreux](https://community.graylog.org/u/cyrilvigreux)\
**Post date:** [February 10, 2021, 7:48am UTC](https://community.graylog.org/t/extractor-for-wallix-message/18751/1 "2021-02-10T07:48:32Z")

</div>

Hello all,  
i try to send log from my wallix bastion to graylog  
message are formated in RFC5424 and i dont know which excrator use. somebody can help me ?

sample of message

[wabauth] action=“authentify” user=“cvigreux” client\_ip=“10.0.4.4” status=“success” infos=“diagnostic [‘dc1-vm-addc01’ -password- authentication succeeded]”

---

<div class="post-metadata">

**Author:** ![dickinsonzach](https://avatars.discourse-cdn.com/v4/letter/d/e19b73/32.png) [@dickinsonzach](https://community.graylog.org/u/dickinsonzach)\
**Post date:** [February 10, 2021, 1:45pm UTC](https://community.graylog.org/t/extractor-for-wallix-message/18751/2 "2021-02-10T13:45:21Z")

</div>

From: [Ingest syslog — Graylog 4.0.0 documentation](https://docs.graylog.org/en/4.0/pages/sending/syslog.html)

“Graylog is able to accept and parse RFC 5424 and RFC 3164 compliant syslog messages and supports TCP transport with both the octet counting or termination character methods. UDP is also supported and the recommended way to send log messages in most architectures.”

Syslog TCP or Syslog UDP should work depending on what protocol your client is using.

Thank you, Zach.

---

<div class="post-metadata">

**Author:** ![cyrilvigreux](https://avatars.discourse-cdn.com/v4/letter/c/f475e1/32.png) [@cyrilvigreux](https://community.graylog.org/u/cyrilvigreux)\
**Post date:** [February 10, 2021, 2:03pm UTC](https://community.graylog.org/t/extractor-for-wallix-message/18751/3 "2021-02-10T14:03:19Z")

</div>

Hello??

my device Wallix send log under format RFC5424. Graylog receive correctly but all the filed are not correctly identify. i think the root cause is the space beetwen each key. probably we should create extractor but i dont know which one

---

<div class="post-metadata">

**Author:** ![dickinsonzach](https://avatars.discourse-cdn.com/v4/letter/d/e19b73/32.png) [@dickinsonzach](https://community.graylog.org/u/dickinsonzach)\
**Post date:** [February 10, 2021, 2:22pm UTC](https://community.graylog.org/t/extractor-for-wallix-message/18751/4 "2021-02-10T14:22:11Z")

</div>

I have done two things when running into this. Do a RAW input or test to another basic syslog server and troubleshoot from there. Thank you, Zach.

---

<div class="post-metadata">

**Author:** ![cyrilvigreux](https://avatars.discourse-cdn.com/v4/letter/c/f475e1/32.png) [@cyrilvigreux](https://community.graylog.org/u/cyrilvigreux)\
**Post date:** [February 11, 2021, 8:26am UTC](https://community.graylog.org/t/extractor-for-wallix-message/18751/5 "2021-02-11T08:26:40Z")

</div>

thank you Zach, but i dont understand what you mind about “do a raw input”

---

<div class="post-metadata">

**Author:** ![dickinsonzach](https://avatars.discourse-cdn.com/v4/letter/d/e19b73/32.png) [@dickinsonzach](https://community.graylog.org/u/dickinsonzach)\
**Post date:** [February 11, 2021, 8:45am UTC](https://community.graylog.org/t/extractor-for-wallix-message/18751/6 "2021-02-11T08:45:05Z")

</div>

Good morning, in stead of creating a Syslog TCP or UDP input; create a Raw/Plaintext TCP or UDP input.

![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/2/2be36d479c1fd16ac72d887b57dabbdfc2f16564.png)

I’ve done this for troubleshooting. And then once I’ve gotten the client sending correctly, delete it and re-create as Syslog TCP or UDP.

For a few devices, I had to leave them on Raw/Plaintext.

Thank you, Zach.

---

<div class="post-metadata">

**Author:** ![cyrilvigreux](https://avatars.discourse-cdn.com/v4/letter/c/f475e1/32.png) [@cyrilvigreux](https://community.graylog.org/u/cyrilvigreux)\
**Post date:** [February 11, 2021, 10:08am UTC](https://community.graylog.org/t/extractor-for-wallix-message/18751/7 "2021-02-11T10:08:35Z")

</div>

I understand, your are right it’s sometime a solution… In ma case il thinking create extractor for identify each field …the problem is that key of message are separated by space and graylog do not separate correctly

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [February 25, 2021, 10:08am UTC](https://community.graylog.org/t/extractor-for-wallix-message/18751/8 "2021-02-25T10:08:41Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
