I’m trying to combine two grok fields to a single field.
Example: Currently my grok extractors has field “src_ip” and “dst_ip”. Now I want to use the pipeline rules to combine both the field src_ip and dst_ip to a single field with name “src_dst_ip”.
How do I achieve this with pipeline rules? , Please post me the example.rule creation.Thanks
I’m trying with the below rule in the pipeline and it does not show in a search field.
rule "Combine src and dst field" when has_field("$message.src_ip") && has_field("$message.dst_ip") then let src_dst_ip = concat( "$message.src_ip" , "$message.dst_ip" ) ; end
src_ip = 192.168.1.1
dst_ip = 10.1.1.1
src_dst_ip = 192.168.1.1 , 10.1.1.1