I'm collecting files written by syslog from Cisco ASA and I'd like to change the source from the filename to a value extracted from _raw. It's not possible right now to send the syslog directly to the edge node.
I've tried evaling source to __raw.match(/\b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b/) The output on value expression seems right but the source field doesn't change. Is this possible?



