Hi,
I’m trying to see if I can avoid ‘Processing Pipeline’ with the following configuration,
Each Input > Extractor > Streams > Send to respective indices.
This way, I can have 1 extractor to 1 stream.
Do you think this is okay?
Hi,
I’m trying to see if I can avoid ‘Processing Pipeline’ with the following configuration,
Each Input > Extractor > Streams > Send to respective indices.
This way, I can have 1 extractor to 1 stream.
Do you think this is okay?
@syntax
Hello,
I believe this can be done.
What version of Graylog are you using?
Is this a single node or a cluster?
How did you configure your extractor?
What kind of INPUT are you using to ingest logs?
How is your stream rules configured to filter out messages?