I am new to the pipeline feature in Graylog. I am trying to set up a pipeline rule but after going through soo many sources not able to find a suitable one.
Rule definition: If the “message:” contains “failed” then add a new field.
Message format is like: (field: value)
message: [2018-07-19 10:33:10,053] admin finish [2486:failed] AllServers admin/- “-/-”[-]
I need help with 2 things basically:
- writing the “when” condition for matching if “failed” string present in the message.
- extracting job id (2486) from the message and store it into a variable.