I have Graylog 2.3.xx and 2.4.xx in my system for logging separate entities, and before I do a long overdue upgrade, I need to solve some issues. There are in both a difficulty to fetch messages from RabbitMQ queue in any other format than raw input. Those events are from Linux machines and in beats. Similar configuration from Windows registries with Winlogbeat gets consumed nicely as GELF AMQP.
Have I missed something important?
Second problem stems from parsing said raw input message. I end up with a “message”:“which includes everything sent”. I don’t care of the rest but I want to find a value for a source withing that message.
How do I access a sub field “source”?
Thank you in advance.