In the stream rules of Graylog (currently I use version 2.3.2) I can’t filter the messages by “gl2_remote_ip”. But I remember that once it worked.
When I use a message to test it against the rules, Graylog no longer filters for “gl2_remote_ip” because it does not exist in the message body.
If I use the same message as above in the search and select the field “gl2_remote_ip”, the IP will be displayed.
I use extractors at the inputs.
What possibilities do I have to use the "gl2_remote_ip " in the stream rule anyway?
Thank you for the great tip. We now use the Graylog in version 2.4, but we are very satisfied with the new version despite beta status. In the version 2.4, we can use the gl2_remote_ip in the pipeline rule without a extra added extractor for this.