I’m Writing an extractor for CSV type of log - this one happened to be IAS straight of out Microsoft NPS. It lives on the Raw Text TCP input. The extractor works just as I want with one exception: I had to use “copy” type of extractor so that I can get the conversion of my fields and that creates a duplicate message of the entire log line. One is for the “message” field and the second one is for the field I had to specify to create the extractor in the first place - that field is called nps_message_log.
Ideally I don’t want either meaning I would like to eliminate completely the original “message” field and my “nps_message_log” field since my converter places all log data into appropriate fields so I am happy with the way it works; just a housekeeping item to avoid duplicating the original raw “message” and my byproduct field “nps_message_log”. Can those both be deleted during extraction so I end up with my nicely formatted fields which already populate with the correct data as a result of the extractor.
Any guidance will be appreciated. Here’s my extractor: