Hi all, sorry for posting about something that’s been asked before, but I’ve been through the docs, and old form posts, and I don’t seem to be able to figure out my issue.
I’ve set up a UDP syslog listener, and configured a Unifi Controller to send logs from my wireless access points into Graylog. This is working, but the source names are not super descriptive (things like “U7PG2,788a215xcaf5,v126.96.36.19915:”).
I’m trying to set up a pipeline to set the source to something else. Here’s what I’ve done so far:
- Under System > Pipelines, I’ve created a new pipeline. The pipeline is connected to the All Messages stream
- Under rules, I’ve added a rule to transform the source field. I’ve tried a LOT of different things, here, and haven’t been able to get anything to work. Here’s the current rule I have in place:
$message.source == “U7PG2,788a215xcaf5,v188.8.131.5215:”
- In stage 0 of the pipeline, I’ve added the rule I created.
I can see in the pipeline that messages are going through, but I don’t see the transformation being applied. I think that I’m missing something somewhere else in the configuration, but I’m not sure where to look next. Can anyone point me in the right direction?