# Sonicwall Pipeline Rules

**URL:** <https://community.graylog.org/t/sonicwall-pipeline-rules/27587>\
**Category:** Pipeline Rules\
**Created:** [February 3, 2023, 8:17pm UTC](https://community.graylog.org/t/sonicwall-pipeline-rules/27587 "2023-02-03T20:17:31Z")\
**Posts on this page:** 1\
**Showing post:** 19

<div class="post-metadata">

**Author:** ![poisedforflight](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/poisedforflight/32/6729_2.png) [@poisedforflight](https://community.graylog.org/u/poisedforflight)\
**Post date:** [October 31, 2023, 4:01pm UTC](https://community.graylog.org/t/sonicwall-pipeline-rules/27587/19 "2023-10-31T16:01:38Z")

</div>

I am trying to implement these rules one at a time but it does not appear like anything is being done. I am showing 0 messages being processed:

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/8/8a8c9080fe22da9f46ba7cc0784e8fcdbd007e4d.png)

```auto
rule "Extract: Sonicwall Extraction"
when
    has_field("source") AND contains(to_string($message.source), "192.168.1.1", true)
then
    set_fields(
        fields:key_value(
            value:to_string($message.message),
            //remove double quotes from keys and values
            trim_value_chars:"\"", 
            trim_key_chars:"\""
            )
        );
end

```

Screenshot does not show it but it’s tied to the correct stream.

Message from stream:

![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/b/b5340a92948abe30d4b14ecd55292ed580ce387d.png)

---

_[View the full topic](https://community.graylog.org/t/sonicwall-pipeline-rules/27587)._
