Grok Extractor Help

I am new to Grok Extractors and I am trying to extract some fields from Logstash.

Example Message:
Nov 9 08:53:00 rsgpchkd[867]: Portforwarding for rsgcadc123215 on /dev/pts/0, destination

I am attempting to pull out anything after the : and tie the destination IP to it. In this case it would be Portforwarding

I have looked at several things, but have to figured out how to accomplish this.

Welcome to our community! :smiley:

Can you share what you have tried so far?

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.