New Pipeline rule to copy value and recreate with new name

(Zachary Rosing) #1

I am currently pulling PFSense logs into Graylog and want to interface it with Grafana. I have the datasource set up, but it wont pull any data because its looking for the value src_ip and not SourceIP, which is how Graylog is seeing it. I’ve already set up the rule for converting the UTC timestamp into real_timestamp, but cannot figure out the rule for converting SourceIP to src_ip, or copying that field data into a new field

0 Likes

#2

you can do it with extractors or with pipeline.

0 Likes

(Zachary Rosing) #3

I’m aware that I CAN do it, I’m just having trouble doing it. I could use assistance on the Pipeline rule to add this.

0 Likes

#4

oh, in this case, do whateveryouwant, whereveryouwant.
please share information, and we can do something with it. without it what would you like?
without information we can’t find a mistype, or a logical error.

0 Likes

(Zachary Rosing) #5

I am looking to fix this that is currently not working to copy the sourceip value and put it in src_ip field.

rule “set_source_ip”
when
has_field(“sourceip”)
then
set_field(“src_ip”, “sourceip”);
end

0 Likes

#7

if you check the graylog docs do you see any difference between your and the docs’ field usage?

http://docs.graylog.org/en/2.4/pages/pipelines/rules.html

1 Like

(system) closed #8

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.

0 Likes