I’m trying to create an extractor for unbound DNS request logs.
unbound: [31543:1] info: 10.2.2.1 ahostname-com A IN
Extractor Type: regex
Regex (confirmed working): [redacted. the forum software thinks I have links in my post)
Condition (confirmed working): [redacted: the forum software thinks I have links in my post)
Store as field: dnslookupdata
Converter: CSV to fields
Field names: dns_srcip dns_req dns_rectype dns_class
Separator character: (I pressed space bar one time)
Quote character: (I tried leaving blank but it doesn’t work so left default ")
Escape character: \
The regexes work but the converter fails. Is using a “CSV to fields” a suitable way to parse messages that are delimited with spaces? My goal is to grab all fields in a single extractor. I’m new to Graylog. Thanks.