Message structure
This block is used to obtain data processed by the program. There is a possibility to obtain data from message dictionary – key data, meta, raw raw_real. There is special value event for accessing whole structure.
Difference between raw and raw_real is on raw is already stripped to only valid syslog data - offset is applied, but in raw_real value is not stripped.
XML representation of message block
<xml xmlns="http://www.w3.org/1999/xhtml">
<block type="message">
<field name="OBJECT">msg</field>
</block>
<block type="message">
<field name="OBJECT">meta</field>
</block>
<block type="message">
<field name="OBJECT">raw</field>
</block>
<block type="message">
<field name="OBJECT">event</field>
</block>
</xml>
data:image/s3,"s3://crabby-images/ef400/ef40024054018b7bb6e2369c7522b5c2b0e313a8" alt="Block "Message""
Block “Message”
data:image/s3,"s3://crabby-images/1eb9c/1eb9c9b7b0687f03f5cf72fe4c5fe46d308acc03" alt="Example of "message" block"
Example of “message” block
Message block is used twice in the example:
- If text message row: Reads data from “raw” key and then compares, if it contains word admin. If yes, it returns boolean value “true”.
- Update dictionary row: updates dictionary “message” key “data” by dictionary “item”.
Login permitted from 192.168.10.1/1234 to inside:192.168.1.1/https for user admin
data:image/s3,"s3://crabby-images/73d99/73d99bf012cff3c4133f66880c939313bbfe01a4" alt="Results of the "message" block"
Results of the “message” block