Hi there

I have a bunch of extractor rules for our syslog INPUT. That means I
actually have a UDP, TCP and TCP/TLS INPUT channel for syslog - and
obviously want the extractors to be the same over the three of them

Currently I have to edit one of them, get new changes working, and then
delete all the extractor rules from the other two INPUT channels (which
means clicking on DELETE-OK dozens of times) - so that I can then do a
"export->import" of the updated set. during this process it means I've got
incoming data that isn't having those extractors applied to them

I'm sure there's some way I could do the same thing with curl/etc, but
adding a "replace extractors" to the "import extractors/export extractors"
dropdown list would be much easier?

-- 
Cheers

Jason Haar
Information Security Manager, Trimble Navigation Ltd.
Phone: +1 408 481 8171
PGP Fingerprint: 7A2E 0407 C9A6 CAF6 2B9F 8422 C063 5EBB FE1D 66D1

-- 
You received this message because you are subscribed to the Google Groups 
"Graylog Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/graylog2/CAFChrgK-Tyz%2BD03V36KtS8Xq4-%3DR9P4EPhahpfgFZX4XKLF5mQ%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to