filter chaining question

Description

I am attempting to filter through grok with named fields, then filter through a custom filter.

After grok when I call the custom filter the event seems to be the same as before grok.

I am confused on how to chain filters and maintain the changes as the event trickles through them.

I took the basic DNS filter and started with that.

The grok filter works, if I run it without the second filter for crowd I get the results I want in output.

Gliffy Diagrams

Activity

Show:

Details

Assignee

Reporter

Created July 3, 2014 at 7:12 PM
Updated July 8, 2014 at 4:48 PM
Loading...