Installed the reighnman “Windows DNS Content Pack” today. I’m using the “Sidecar method” because I had issues getting nxlog to play ball. It works well so far.
What doesn’t seem to be working though is the Extractor that replaces the parenthesized numbers with a period.
When I go to Inputs->Mange Extractors->Edit and click “Try”, it’s working. For example,
(3)fun(3)net(0) is converted to
.fun.net. (I could do without the leading and trailing dots, but that’s another day). It is set to “Cut” instead of “Copy” and the way I understand things, it should replace the Name field with the version with periods instead of the parentheses.
But, when I look at the Messages in Search, it shows the Name with the parentheses.
Am I looking at this wrong, or is there something I’m just missing?
Here is the Extractor Test:
Here is a snip of the Search result showing the Name field.