I am trying to overwrite the “source” field with gl2_remote_ip but it seems this var is empty, or non-existent.
The rule I am using is:
rule "Set Source IP" when has_field("message") then set_field("source_ip", to_string($message.gl2_remote_ip)); set_field("test", "yes"); end
The “test” field I am using as a check gets properly set but source_ip does not.
If I try to set the field “source_ip” with a fixed string, it is ok, it seems that $message.gl2_remote_ip cannot be used in this context.
Running Graylog 2.4.3, installed the OVA VM.