jbsky / graylog

Graylog extractor

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Can't import pfsense extractor into version 5.1

InSelfControll opened this issue · comments

Import operation completed
Import results: 20 extractor(s) imported, 6 error(s).

commented

Hello :),

It says it works with Graylog 5, not 5.1.

You're asking for an evolution, I think it's a good exercise for you to find the solution.

Thank you for your understanding.

Best regards,

Hey, thanks for answering,
I'm pretty new to graylog I still have a lot to learn about this system and how to work with it to get exactly what I want to get.
I'll try to understand how this extractors work and probably I'll even add sendmail / postfix and etc to this graylog system in the feature.

Hey I get the same result on graylog 5.0 are you sure it should work ?
I have created a new instances with version 5.0 and same results.

I can confirm the extractors work for 5.1. The reason why they are failing is because you don't have the lookup tables created yet. I was having the same issue and it was driving me nuts trying to figure it out. I went through and verified which ones failed for both extractor files, and the only ones that failed were the lookup table extractor types. All others were able to import with no problem. You will need to download the Maxmind mmdb files with a free account and create your lookup tables pointing at those files. After I did this, I was able to import the lookup table extractor types with no issues.

commented

No details on the problem encountered, I close this problem.