# Extractors not showing in all fields

**URL:** <https://community.graylog.org/t/extractors-not-showing-in-all-fields/5020>\
**Category:** Graylog Central (peer support)\
**Created:** [April 18, 2018, 3:42pm UTC](https://community.graylog.org/t/extractors-not-showing-in-all-fields/5020 "2018-04-18T15:42:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![unixinthebox](https://avatars.discourse-cdn.com/v4/letter/u/df705f/32.png) [@unixinthebox](https://community.graylog.org/u/unixinthebox)\
**Post date:** [April 18, 2018, 3:42pm UTC](https://community.graylog.org/t/extractors-not-showing-in-all-fields/5020/1 "2018-04-18T15:42:00Z")

</div>

Example message  
oratst01 audit\_log: type=SYSCALL msg=audit(1523563770.592:72523244): arch=c000003e syscall=82 success=yes exit=0 a0=7f043000f910 a1=7f043000fe50 a2=7f043000fe50 a3=442f676e69646e65 items=4 ppid=11580 pid=19953 auid=1000 uid=1000 gid=1000 euid=1000 suid=1000 fsuid=1000 egid=1000 sgid=1000 fsgid=1000 tty=(none) ses=15056 comm=“java” exe="/u01/oracle/product/agent/agent\_13.2.0.0.0/oracle\_common/jdk/bin/java" key=“delete”  
Wrong example? You can .  
Extractor configuration  
Extractor type  
Regular expression

Source field  
message

Regular expression

^(.+)audit\_log  
The regular expression used for extraction. First matcher group is used. Learn more in the documentation.  
Extractor preview  
oratst01  
Condition  
Always try to extract  
Only attempt extraction if field contains string  
Only attempt extraction if field matches regular expression  
Extracting only from messages that match a certain condition helps you avoiding wrong or unnecessary extractions and can also save CPU resources.  
Store as field  
hostname  
Choose a field name to store the extracted value. It can only contain alphanumeric characters and underscores. Example: http\_response\_code.  
Extraction strategyCopyCut  
Do you want to copy or cut from source? You cannot use the cutting feature on standard fields like message and source.  
Extractor title  
linux-auditd-hostname  
A descriptive name for this extractor.  
Add converter  
Select a converter  
Add converters to transform the extracted value.

See this extractors is being recognized, but it doesn’t show in all fields.

Is this a bug ?

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [April 18, 2018, 3:51pm UTC](https://community.graylog.org/t/extractors-not-showing-in-all-fields/5020/2 "2018-04-18T15:51:07Z")

</div>

Please provide some screenshots and a clear formulation what you want to achieve and what doesn’t work.

---

<div class="post-metadata">

**Author:** ![unixinthebox](https://avatars.discourse-cdn.com/v4/letter/u/df705f/32.png) [@unixinthebox](https://community.graylog.org/u/unixinthebox)\
**Post date:** [April 18, 2018, 4:37pm UTC](https://community.graylog.org/t/extractors-not-showing-in-all-fields/5020/3 "2018-04-18T16:37:10Z")

</div>

I think I fixed the issue.

Thanks for your response !!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [May 2, 2018, 4:37pm UTC](https://community.graylog.org/t/extractors-not-showing-in-all-fields/5020/4 "2018-05-02T16:37:45Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
