Are you naming your captures in your Grok Pattern and have “Named captures only” checked in the configuration? Can you post the GROK and relevant extractor settings?
Condition: Only attempt extraction if field contains string
Field contains string: DstIP
Extraction strategy: Copy
And then a title for the Extractor.
I have tried both Cut and Copy, and Have tried with Named Checked and Unchecked.
I also have started to notice that when I restarted Graylog, Initially I would see the fields and data, until I started getting a Kafka file lock error in the /var/log/graylog-server/server.log
We aren’t set up with Kafka so I guess I won’t be much help - I poked around a bit and found more on Kafka file locks Graylog Kafka file lock hope that gives you some leads! Good luck!
So it seems, I just have to wait like 12 hours for the fields to start showing data and extraction. Weird that it would take that long. but it is working now.
yoou should check how much data is in your journal of Graylog and if you have all servers in the same timezone … and the messages are stored with the correct date.