I have successfully configured graylog with windows server using nxlog. I am able to see the logs coming in graylog. But there are some issues.
- Windows log send data as raw text and xml.
- graylog is able to pickup xml just fine and index the data in the fields and raw text goes into full_message and message fields.
- some of the xml data is not in shape. kindly check the attached screenshot of field Failure reason.
How can i extract the Failure Reason and put inside another field?
I am trying using extractors but so far no luck.