I am new to Grok Extractors and I am trying to extract some fields from Logstash.
Nov 9 08:53:00 192.168.131.6 rsgpchkd: Portforwarding for rsgcadc123215 on /dev/pts/0, destination 10.208.203.30:22
I am attempting to pull out anything after the : and tie the destination IP to it. In this case it would be Portforwarding 10.208.203.30:22
I have looked at several things, but have to figured out how to accomplish this.