# Replacing the Name in the Source Field

**URL:** <https://community.graylog.org/t/replacing-the-name-in-the-source-field/12447>\
**Category:** Graylog Central (peer support)\
**Created:** [October 18, 2019, 9:21pm UTC](https://community.graylog.org/t/replacing-the-name-in-the-source-field/12447 "2019-10-18T21:21:18Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![brigzzy](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/brigzzy/32/5190_2.png) [@brigzzy](https://community.graylog.org/u/brigzzy)\
**Post date:** [October 18, 2019, 9:21pm UTC](https://community.graylog.org/t/replacing-the-name-in-the-source-field/12447/1 "2019-10-18T21:21:18Z")

</div>

Hi all, sorry for posting about something that’s been asked before, but I’ve been through the docs, and old form posts, and I don’t seem to be able to figure out my issue.

I’ve set up a UDP syslog listener, and configured a Unifi Controller to send logs from my wireless access points into Graylog. This is working, but the source names are not super descriptive (things like “U7PG2,788a215xcaf5,v4.0.59.10615:”).

I’m trying to set up a pipeline to set the source to something else. Here’s what I’ve done so far:

1. Under System \> Pipelines, I’ve created a new pipeline. The pipeline is connected to the All Messages stream
2. Under rules, I’ve added a rule to transform the source field. I’ve tried a LOT of different things, here, and haven’t been able to get anything to work. Here’s the current rule I have in place:

rule “AP1”  
when  
$message.source == “U7PG2,788a215xcaf5,v4.0.59.10615:”  
then  
set\_field(“source”, “AP1”);  
end

1. In stage 0 of the pipeline, I’ve added the rule I created.

I can see in the pipeline that messages are going through, but I don’t see the transformation being applied. I think that I’m missing something somewhere else in the configuration, but I’m not sure where to look next. Can anyone point me in the right direction?

Thanks!

---

<div class="post-metadata">

**Author:** ![shoothub](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/shoothub/32/6412_2.png) [@shoothub](https://community.graylog.org/u/shoothub)\
**Post date:** [October 21, 2019, 7:52am UTC](https://community.graylog.org/t/replacing-the-name-in-the-source-field/12447/2 "2019-10-21T07:52:32Z")

</div>

Hello,

1. You probably didn’t use search very hard, check this topic:  
[Change source name through pipeline example?](https://community.graylog.org/t/change-source-name-through-pipeline-example/5459/6)

2. Your rule condition has 2 problems: First you don’t use function to\_string($message.source) which is neccesary. Second you use too specific condition, if you update firmware your condition will not match. I suggest to change condition to something more descriptive like:  
`contains(to_string($message.source), "U7PG2,788a215xcaf5")` or only  
`contains(to_string($message.source), "788a215xcaf5")` which is probably mac address of AP

3. You can also use lookup table if you have many APs, create CSV file and use function `lookup_value()`

---

<div class="post-metadata">

**Author:** ![brigzzy](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/brigzzy/32/5190_2.png) [@brigzzy](https://community.graylog.org/u/brigzzy)\
**Post date:** [October 23, 2019, 10:16pm UTC](https://community.graylog.org/t/replacing-the-name-in-the-source-field/12447/3 "2019-10-23T22:16:07Z")

</div>

Hey, thank you so much for the guidance! I managed to get it working as follows:

rule “AP1”  
when  
to\_string($message.source) == “U7PG2,788gt050as3w,v4.0.54.10625:”  
then  
set\_field(“source”, “AP1”);  
end

I’ll try using the contains method as you described. I like the idea of not updating the rules when the firmware changes.

Thanks again!

---

<div class="post-metadata">

**Author:** ![brigzzy](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/brigzzy/32/5190_2.png) [@brigzzy](https://community.graylog.org/u/brigzzy)\
**Post date:** [October 23, 2019, 10:29pm UTC](https://community.graylog.org/t/replacing-the-name-in-the-source-field/12447/4 "2019-10-23T22:29:46Z")

</div>

One thing that I noticed, which I think was part of my confusion, is that it seems to take a while for the changes in the pipeline to kick in. I got into work today, after leaving this in it’s previous state for about 5 days, and found that it was working (using function to\_string($message.source), as you described).

Is there any reason for the delay in changing the pipeline, to seeing the changes in the search?

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [October 25, 2019, 5:15am UTC](https://community.graylog.org/t/replacing-the-name-in-the-source-field/12447/5 "2019-10-25T05:15:47Z")

</div>

he @brigzzy - as the changes are instand, I guess your messages are not “sync in time” and that is the reason it appears to be not in sync.

Check the time on your devices

---

<div class="post-metadata">

**Author:** ![brigzzy](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/brigzzy/32/5190_2.png) [@brigzzy](https://community.graylog.org/u/brigzzy)\
**Post date:** [October 25, 2019, 3:57pm UTC](https://community.graylog.org/t/replacing-the-name-in-the-source-field/12447/6 "2019-10-25T15:57:14Z")

</div>

Thanks Jan, that’s definitely the issue. The devices are in UTC, and the Graylog server is in PST. Looks pretty instant now!

Cheers!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [November 8, 2019, 3:57pm UTC](https://community.graylog.org/t/replacing-the-name-in-the-source-field/12447/7 "2019-11-08T15:57:14Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
