Hi,
I am new in graylog. It should be an easy question, sorry!
I have a json log messages but can not run my extractor. I think the problem is program name and pid(program[91129]: ) in the beginning of the message body. any way to omit this part?!
sample message body:
program[91129]: {“timestamp”: “2019-07-29”, “flow_id”: 1964529267423472, “in_iface”: “eth0”, “event_type”: “dns”, “src_ip”: “192.168.10.6”, “src_port”: 45885, “dest_ip”: “8.8.8.8”, “dest_port”: 53, “proto”: “UDP”, “dns”: {“type”: “query”, “id”: 1989, “rrname”: “detertal.firefox.com”, “rrtype”: “A”, “tx_id”: 0}}