@michmoor said in netflow and graylog:
Few things ive been able to do with GROK parsing is not to clean up my unbound log files and create fields that are important to me and good for tracking.
I'm running Graylog 5.2 now, had to build gcc 11.1.0+ from source, it took a few hours in my raspberry pi 4 but it is working :)
@michmoor said in netflow and graylog:
I just dont know how to enrich data using dns for IP lookups but thats ok
I'm using PTR for that purpose, if there is something I can help, just let me know.
@michmoor said in netflow and graylog:
Few things ive been able to do with GROK parsing is not to clean up my unbound log files and create fields that are important to me and good for tracking.
Ow, that is really nice :) If it is possible, can you share how you are getting those statistics from Unbound ?