# Pipeline simulator and message fields

**URL:** <https://community.graylog.org/t/pipeline-simulator-and-message-fields/4605>\
**Category:** Graylog Central (peer support)\
**Created:** [March 16, 2018, 9:14pm UTC](https://community.graylog.org/t/pipeline-simulator-and-message-fields/4605 "2018-03-16T21:14:20Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![digitallachance](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/digitallachance/32/1955_2.png) [@digitallachance](https://community.graylog.org/u/digitallachance)\
**Post date:** [March 16, 2018, 9:14pm UTC](https://community.graylog.org/t/pipeline-simulator-and-message-fields/4605/1 "2018-03-16T21:14:20Z")

</div>

I’m trying to figure out this pipeline feature for the purpose of dropping some messages that I simply do not care about. Basically, I’m looking to do blacklisting. In order to do that filtering, I am looking for the existence of specific fields that would be created by an extractor. When I go to the pipeline simulator and paste in a copy of the raw message, select a Message input, it doesn’t seem to run that message through any extractor.

What am I missing here?

I am using the “All messages” stream.

The rule that I am trying to use is:

rule “has firewall fields”  
when  
has\_field(“FW\_Src\_IPv4”) && has\_field(“FW\_Dst\_IPv4”)  
then  
end

Thanks!

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [March 17, 2018, 7:49am UTC](https://community.graylog.org/t/pipeline-simulator-and-message-fields/4605/2 "2018-03-17T07:49:17Z")

</div>

what is the processing order over at `System > Configuration`? the pipelines should be after the _Message filter Chain_

and your rule need the drop - [http://docs.graylog.org/en/2.4/pages/pipelines/functions.html#drop-message](http://docs.graylog.org/en/2.4/pages/pipelines/functions.html#drop-message) - if you really want to drop.

---

<div class="post-metadata">

**Author:** ![digitallachance](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/digitallachance/32/1955_2.png) [@digitallachance](https://community.graylog.org/u/digitallachance)\
**Post date:** [March 17, 2018, 8:24am UTC](https://community.graylog.org/t/pipeline-simulator-and-message-fields/4605/3 "2018-03-17T08:24:38Z")

</div>

Sorry, I failed to mention that I have already ensured that the pipeline is after the _Message filter Chain_.

The rule I posted was only the one to figure out if the message is from the firewall. I have another rule that will do the drop of the message.

As I indicated earlier, the field that should have been created by the extractor are not showing up in the simulator.

How would I troubleshoot that?

Thanks!

---

<div class="post-metadata">

**Author:** ![digitallachance](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/digitallachance/32/1955_2.png) [@digitallachance](https://community.graylog.org/u/digitallachance)\
**Post date:** [March 20, 2018, 6:11pm UTC](https://community.graylog.org/t/pipeline-simulator-and-message-fields/4605/4 "2018-03-20T18:11:05Z")

</div>

Bump this thread. Jan?

Thanks!

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [March 21, 2018, 8:41am UTC](https://community.graylog.org/t/pipeline-simulator-and-message-fields/4605/5 "2018-03-21T08:41:02Z")

</div>

the problem with the simulator is, that the message need to look like a message that is received by graylog - if no extractor runs on that message it looks like the message did not look like raw message for that input.

For Cisco devices that would be something like:

```auto
<189>91: *Mar 15 2018 21:48:41.663 UTC: %SYS-5-CONFIG_I: Configured from console by cisco on vty0 (192.168.200.1)

```

---

<div class="post-metadata">

**Author:** ![digitallachance](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/digitallachance/32/1955_2.png) [@digitallachance](https://community.graylog.org/u/digitallachance)\
**Post date:** [March 22, 2018, 6:18pm UTC](https://community.graylog.org/t/pipeline-simulator-and-message-fields/4605/6 "2018-03-22T18:18:20Z")

</div>

Ok, so if I use the following, which is the taken from the full\_message field in one of the events and supply that to the “Raw Message” field:

`<150>Mar 22 2018 12:06:58 Henderson-ASA : %ASA-6-106100: access-list 200 denied tcp inside/10.55.172.187(60909) -> outside/157.55.170.113(5671) hit-cnt 1 first hit [0x912b3b50, 0xda8ccb71]`

Which is taken from an ASA firewall, the extractors do not fire at all. The extractors did work properly when this message came in - it’s just the simulator is not.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [April 5, 2018, 6:18pm UTC](https://community.graylog.org/t/pipeline-simulator-and-message-fields/4605/7 "2018-04-05T18:18:28Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
