HI Guys,
I’m trying to add an extractor of a stream (msg=“Gateway Anti-Virus Alert: (Cloud Id: 75044252) Browsefox-6628766-0 (Adware) blocked.”) and i want to extract from the full message only Adware, Trojan, ransomware, etc)
I have tried many options but none of them is suitable.
Any idea how to extract only that specific word?
Thanks
Laurentiu
i have create a grok pattern like adware|ransomware|trojan etc and than i have create extractor to full message with %{name _grock patter:action} and it worked.