# Extractor regex fields not appear when simulating pipeline

**URL:** <https://community.graylog.org/t/extractor-regex-fields-not-appear-when-simulating-pipeline/19546>\
**Category:** Graylog Central (peer support)\
**Tags:** pipeline-rules, debuggingpl\
**Created:** [April 21, 2021, 5:34am UTC](https://community.graylog.org/t/extractor-regex-fields-not-appear-when-simulating-pipeline/19546 "2021-04-21T05:34:24Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Howard](https://avatars.discourse-cdn.com/v4/letter/h/90ced4/32.png) [@Howard](https://community.graylog.org/u/Howard)\
**Post date:** [April 21, 2021, 5:34am UTC](https://community.graylog.org/t/extractor-regex-fields-not-appear-when-simulating-pipeline/19546/1 "2021-04-21T05:34:24Z")

</div>

I extracted two fields in the input, and I had changed message filter chain before Pipeline processor.  
I used debug to check the values and it turned null with the following rule

rule “remote session”  
when  
true  
then  
let debug\_message = concat("user\_source: ", to\_string($message.user\_source));  
debug(debug\_message);  
let debug\_message1 = concat("user\_been\_used: ", to\_string($message.user\_been\_used));  
debug(debug\_message1);  
end

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/d/dacb06304ae704ed5939197873259a9f314bfce4.png)

---

<div class="post-metadata">

**Author:** ![tmacgbay](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/tmacgbay/32/3878_2.png) [@tmacgbay](https://community.graylog.org/u/tmacgbay)\
**Post date:** [April 21, 2021, 12:09pm UTC](https://community.graylog.org/t/extractor-regex-fields-not-appear-when-simulating-pipeline/19546/2 "2021-04-21T12:09:14Z")

</div>

Under **System/Configurations-\>Message Processor Configurations** do you have the _Message Filter Chain_ coming before the _Pipeline Processor_? If you want your extractors to work before the pipeline, it should…

---

<div class="post-metadata">

**Author:** ![Howard](https://avatars.discourse-cdn.com/v4/letter/h/90ced4/32.png) [@Howard](https://community.graylog.org/u/Howard)\
**Post date:** [April 22, 2021, 1:08am UTC](https://community.graylog.org/t/extractor-regex-fields-not-appear-when-simulating-pipeline/19546/3 "2021-04-22T01:08:09Z")

</div>

I have set message filter chain before pipeline processor

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/1/12b4b2dd68078f2a381cc4d1d64b6893033b3032.png)

---

<div class="post-metadata">

**Author:** ![shoothub](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/shoothub/32/6412_2.png) [@shoothub](https://community.graylog.org/u/shoothub)\
**Post date:** [April 22, 2021, 10:22am UTC](https://community.graylog.org/t/extractor-regex-fields-not-appear-when-simulating-pipeline/19546/4 "2021-04-22T10:22:34Z")

</div>

It’s your debug log from real message or only from simulator? I don’t know if it’s working from simulator if you expect so.

---

<div class="post-metadata">

**Author:** ![tmacgbay](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/tmacgbay/32/3878_2.png) [@tmacgbay](https://community.graylog.org/u/tmacgbay)\
**Post date:** [April 22, 2021, 2:05pm UTC](https://community.graylog.org/t/extractor-regex-fields-not-appear-when-simulating-pipeline/19546/5 "2021-04-22T14:05:19Z")

</div>

Can you post the original message and what you are doing in the extractor?

---

<div class="post-metadata">

**Author:** ![Howard](https://avatars.discourse-cdn.com/v4/letter/h/90ced4/32.png) [@Howard](https://community.graylog.org/u/Howard)\
**Post date:** [April 23, 2021, 1:54am UTC](https://community.graylog.org/t/extractor-regex-fields-not-appear-when-simulating-pipeline/19546/6 "2021-04-23T01:54:57Z")

</div>

the message :pam\_unix(remote:session): session opened for user yyyyy by wwww(uid=0)

the extractor setting:

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/a/a1716b7635795a285ddd246d376460cc5db92813.png)

---

<div class="post-metadata">

**Author:** ![Howard](https://avatars.discourse-cdn.com/v4/letter/h/90ced4/32.png) [@Howard](https://community.graylog.org/u/Howard)\
**Post date:** [April 23, 2021, 1:55am UTC](https://community.graylog.org/t/extractor-regex-fields-not-appear-when-simulating-pipeline/19546/7 "2021-04-23T01:55:32Z")

</div>

continued:

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/0/0fdbe281344b2aaee3655b1a54628c52445cdc50.png)

---

<div class="post-metadata">

**Author:** ![Howard](https://avatars.discourse-cdn.com/v4/letter/h/90ced4/32.png) [@Howard](https://community.graylog.org/u/Howard)\
**Post date:** [April 23, 2021, 1:55am UTC](https://community.graylog.org/t/extractor-regex-fields-not-appear-when-simulating-pipeline/19546/8 "2021-04-23T01:55:53Z")

</div>

the real message showed that the extractor worked:

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/e/ef473fb12f6df901250ca339a289d6faff70f519.png)

---

<div class="post-metadata">

**Author:** ![tmacgbay](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/tmacgbay/32/3878_2.png) [@tmacgbay](https://community.graylog.org/u/tmacgbay)\
**Post date:** [April 23, 2021, 11:39am UTC](https://community.graylog.org/t/extractor-regex-fields-not-appear-when-simulating-pipeline/19546/9 "2021-04-23T11:39:30Z")

</div>

Ran some tests on my side and the extractor was not processed in the simulation run despite having the correct Message Input with associated extractor set. Results were same as yours. (I don’t use any extractors in production - all the work is done in pipeline.)

Maybe submit as a bug: [Issues · Graylog2/graylog2-server · GitHub](https://github.com/Graylog2/graylog2-server/issues)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [May 7, 2021, 11:40am UTC](https://community.graylog.org/t/extractor-regex-fields-not-appear-when-simulating-pipeline/19546/10 "2021-05-07T11:40:26Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
