# Help with understanding a few key fundamental conepts of graylog. Raw vs Syslog input

**URL:** <https://community.graylog.org/t/help-with-understanding-a-few-key-fundamental-conepts-of-graylog-raw-vs-syslog-input/22253>\
**Category:** Graylog Central (peer support)\
**Tags:** basic-configuration\
**Created:** [January 5, 2022, 3:19pm UTC](https://community.graylog.org/t/help-with-understanding-a-few-key-fundamental-conepts-of-graylog-raw-vs-syslog-input/22253 "2022-01-05T15:19:59Z")\
**Posts on this page:** 6\
**Page:** 2

<div class="post-metadata">

**Author:** ![NEO-AMiGA](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/neo-amiga/32/10527_2.png) [@NEO-AMiGA](https://community.graylog.org/u/NEO-AMiGA)\
**Post date:** [January 11, 2022, 5:18pm UTC](https://community.graylog.org/t/help-with-understanding-a-few-key-fundamental-conepts-of-graylog-raw-vs-syslog-input/22253/21 "2022-01-11T17:18:21Z")

</div>

OH. MY. GOD! That’s amazing! Thanks! Exactly what I was looking for! Brilliant. 🙏 🙏

 ![Screenshot 2022-01-11 at 18.16.38](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/f/fbb63c377dca78fc636a036e2fb0979c27c064e3.png)

---

<div class="post-metadata">

**Author:** ![riskersen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/riskersen/32/7268_2.png) [@riskersen](https://community.graylog.org/u/riskersen)\
**Post date:** [January 11, 2022, 5:50pm UTC](https://community.graylog.org/t/help-with-understanding-a-few-key-fundamental-conepts-of-graylog-raw-vs-syslog-input/22253/22 "2022-01-11T17:50:54Z")

</div>

Coolio, but for the reference, wireshark seems to offer a syslog filter [Wireshark · Display Filter Reference: Syslog message](https://www.wireshark.org/docs/dfref/s/syslog.html)

Anyways remote IP is a thousand times better, than diving through wireshark for that 😉

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [January 11, 2022, 10:35pm UTC](https://community.graylog.org/t/help-with-understanding-a-few-key-fundamental-conepts-of-graylog-raw-vs-syslog-input/22253/23 "2022-01-11T22:35:08Z")

</div>

Hello,  
Glad you found it your solution 🙂

---

<div class="post-metadata">

**Author:** ![kamils85](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/kamils85/32/9026_2.png) [@kamils85](https://community.graylog.org/u/kamils85)\
**Post date:** [January 12, 2022, 7:34am UTC](https://community.graylog.org/t/help-with-understanding-a-few-key-fundamental-conepts-of-graylog-raw-vs-syslog-input/22253/24 "2022-01-12T07:34:28Z")

</div>

The only issue with this one is that you need to add this field to all tables every time you access graylog but I lived that for years and it didn’t bother me much 😉

Now I grew up and I am using pipeline rule to replace the **source** field with **gl2\_remote\_ip** field and from now on my **source** always shows the same value as **gl2\_remote\_ip**.

Pipeline rule is attached to every message that comes through.

```auto
rule "replace_source_with_ip"
when
  has_field("message")
then
  set_field("source", to_string($message.gl2_remote_ip));
end

```

K.

---

<div class="post-metadata">

**Author:** ![NEO-AMiGA](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/neo-amiga/32/10527_2.png) [@NEO-AMiGA](https://community.graylog.org/u/NEO-AMiGA)\
**Post date:** [January 12, 2022, 8:49am UTC](https://community.graylog.org/t/help-with-understanding-a-few-key-fundamental-conepts-of-graylog-raw-vs-syslog-input/22253/25 "2022-01-12T08:49:20Z")

</div>

I prefer hostnames but I will probably add remote IP in a separate field so it’s saved in message. You could also make a dashboard where you display that field in the view and save it. Sadly it seems like we don’t have control over column width so the formatting has more to wish for. =/

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [January 26, 2022, 8:50am UTC](https://community.graylog.org/t/help-with-understanding-a-few-key-fundamental-conepts-of-graylog-raw-vs-syslog-input/22253/26 "2022-01-26T08:50:02Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.

[Previous page](https://community.graylog.org/t/help-with-understanding-a-few-key-fundamental-conepts-of-graylog-raw-vs-syslog-input/22253.md?page=1)
