Hi all! I would very much like to be able to transform text using an extractor.
My IIS servers log to Graylog using snare. IIS is configured to log the website ID. For efficiency (we host a lot of sites), we log to a single IIS log for all websites. Snare picks up the logs and stuffs them into Graylog. I would like to be able to use an extractor to transform the logged IIS site ID into a website name. For example, W3SVC8 might be transformed to www.example.com. I was really excited when I saw the CSV to field option, but this only tokenizes CSV values already in the message. Is it possible to do a text transform/substitution with an extractor? Thanks! Brantley Hobbs -- You received this message because you are subscribed to the Google Groups "graylog2" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/d/optout.
