# Rexgex Extractor - for pfsense devices

**URL:** <https://community.graylog.org/t/rexgex-extractor-for-pfsense-devices/372>\
**Category:** Graylog Central (peer support)\
**Created:** [March 7, 2017, 4:02pm UTC](https://community.graylog.org/t/rexgex-extractor-for-pfsense-devices/372 "2017-03-07T16:02:59Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![monchito](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/monchito/32/3372_2.png) [@monchito](https://community.graylog.org/u/monchito)\
**Post date:** [March 7, 2017, 4:02pm UTC](https://community.graylog.org/t/rexgex-extractor-for-pfsense-devices/372/1 "2017-03-07T16:02:59Z")

</div>

Hi, all, i want to make and regex extrator for Pfsense device. This device give me a raw message like this:

“\<134\>Mar 7 18:57:53 filterlog: 79,16777216,1469649672,em0,match,pass,out,4,0x0,62,13847,0,DF,6,tcp,60,1.1.1.1,2.2.2.2,54787,80,0,S,3818924332,5840,mss;sackOK;TS;nop;wscale”

For example: i want to get : 2.2.2.2 value (position number: 20 of the message) in the csv string.

Is possible?  
Thanks.

---

<div class="post-metadata">

**Author:** ![derPhlipsi](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/derphlipsi/32/38_2.png) [@derPhlipsi](https://community.graylog.org/u/derPhlipsi)\
**Post date:** [March 7, 2017, 9:19pm UTC](https://community.graylog.org/t/rexgex-extractor-for-pfsense-devices/372/2 "2017-03-07T21:19:36Z")

</div>

Hey @monchito,

take a look at the _CSV To Fields_ converter.  
Steps:

1. Go to the Extractor page of your Input, click _Get Started_.
2. Create an _Copy Input_ extractor on your message field, that copies to itself.
3. At the bottom add and configure a _CSV To Fields_ converter.

Hint: You maybe want to use a GROK Extractor first to filter out `<134>Mar 7 18:57:53 filterlog:` before your actual csv. Something like `filterlog: ${GREEDYDATA:csvString}`

If you only need some specific fields, you could write an GROK Extractor, that marks fields you don’t need as UNWANTED. [Look here](http://docs.graylog.org/en/2.2/pages/extractors.html#using-grok-patterns-to-extract-data) for more details.

Greetings - Phil

---

<div class="post-metadata">

**Author:** ![monchito](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/monchito/32/3372_2.png) [@monchito](https://community.graylog.org/u/monchito)\
**Post date:** [March 8, 2017, 1:00pm UTC](https://community.graylog.org/t/rexgex-extractor-for-pfsense-devices/372/3 "2017-03-08T13:00:39Z")

</div>

Hi Phillipp ! Thanks for reply.

I followed this step:

> take a look at the CSV To Fields converter.  
> Steps:
> 
> 1. Go to the Extractor page of your Input, click Get Started.
> 2. Create an Copy Input extractor on your message field, that copies to itself.
> 3. At the bottom add and configure a CSV To Fields converter.

But i get only the same message. I cant extract anything.

I cant found how extract a message like this, neither Rexgex or Grok because it not have labels  
“\<134\>Mar 7 18:57:53 filterlog: 79,16777216,1469649672,em0,match,pass,out,4,0x0,62,13847,0,DF,6,tcp,60,1.1.1.1,2.2.2.2,”

If were like this (filterlog:79 with label case):  
“\<134\>Mar 7 18:57:53 filterlog: 79,\*\*a:\*\*16777216,\*\*c:\*\*1469649672,\*\*d:\*\*em0,\*\*e:\*\*match,\*\*f:\*\*pass,\*\*g:\*\*out,\*\*h:\*\*4,\*\*i:\*\*0x0,62,13847,0,DF,6,tcp,60,\*\*r:\*\*1.1.1.1,\*\*s:\*\*2.2.2.2,”

```
regex_value: s:?([0-9.]+) result= 2.2.2.2

```

I think, that i have to do something to count between comas.

Please, tell me if i’m not clear, or maybe i missing something.

Thanks!

---

<div class="post-metadata">

**Author:** ![derPhlipsi](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/derphlipsi/32/38_2.png) [@derPhlipsi](https://community.graylog.org/u/derPhlipsi)\
**Post date:** [March 9, 2017, 9:48am UTC](https://community.graylog.org/t/rexgex-extractor-for-pfsense-devices/372/4 "2017-03-09T09:48:53Z")

</div>

Hey,

here are two solutions:

## Solution 1: Getting all fields:

Two Extractors, first a GROK to remove syslog-header (actually, why is it in there?), second a Copy-Input with csv-converter.

 ![](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/1X/c5623ce507f287b549740e2e1e12d2c78d629068.png)  
**The GROK Extractor:**  
 ![](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/1X/7ec04682c9c6c6bef4617680418b83b5f72a8069.png)  
**The Copy-Input with _CSV To Fields_ converter**  
**Note:** In the field names attribute, there are 29 fields needed, since the csv is 29 columns wide. Use appropriate names if they are known for better readability.  
 ![](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/1X/e5ea1863f6ca259549d583ad7167c1023e7f80ed.png)  
**This is the result:**  
 ![](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/1X/7552e97883ef2b3c132c2e2ae9d1d75e6d270e4b.png)

## Solution 2: Only 20th (_n_ th) field.

Use a Split and Index Extractor, that splits on _“,”_ (comma) and set the target index to 20.

 ![](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/1X/e451f1ac57d8a082607beccfb85db066065d8e50.png)  
**The result:**  
 ![](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/1X/557a5109796de7c106999812d6bcdbd8b59cf3ec.png)

Greetings - Phil

**PS:** For your convenience: `value1,value2,value3,value4,value5,value6,value7,value8,value9,value10,value11,value12,value13,value14,value15,value16,value17,value18,value19,value20,value21,value22,value23,value24,value25,value26,value27,value28,value29`

---

<div class="post-metadata">

**Author:** ![monchito](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/monchito/32/3372_2.png) [@monchito](https://community.graylog.org/u/monchito)\
**Post date:** [March 24, 2017, 7:38pm UTC](https://community.graylog.org/t/rexgex-extractor-for-pfsense-devices/372/5 "2017-03-24T19:38:56Z")

</div>

Hi Philipp, i’m coming too late i just configured it ! it works like charm !

Thanks for all !
