Hi Graylog Team,
I am new to graylog.
I have a requirement to create a new field as :- real_ip and real port from a raw log .
I want to use x-forwarded-for value as the real ip field and x-forwarded-port as the real port field. Please refer below log as an example.
Example Log:-
“x-forwarded-for”:“10.2.6.49”,“x-forwarded-proto”:“https”,“x-forwarded-port”:“443”,“host”:“www.example.com”,“x-amzn-trace-id”:“Root=1-623e45i6ii003jjifds”,“sec-ch-ua”:“".Not/A)Brand";v="56", "Google Chrome";v="102", "Chromium";v="102"”,“accept”:“application/json;charset=utf-8,/”,“sec-h-a-mobile”:“?0”,“user-agent”:"Mozilla/4.0 (Windows NT 10.0; Win64; x64) AppleWebKit/527.36 (KHTML, like Gecko) Chrome/102.0.0.0
From this log we can see “x-forwarded-for” value is = 10.2.6.49.
I want to get this value of x-forwarded-for as real_ip = 10.2.6.49
Please help me how can i achieve this using a pipeline rule.
Thanks in advance