Centralising logs with rsyslog and parsing them with Graylog extractors
brendan.abolivier.bzh
brendan.abolivier.bzh
Also: what happens if there is a typo in one of the rules and a log entry doesn't get parsed? Does Graylog/grok have some indication that the log doesn't match? And where the mismatch starts? Because liblognorm does.
Regarding your latter point, as I mentionned, a pattern fails silently if it doesn't match a log entry while parsing incoming entries. That's why Graylog requires you to load a log entry example when creating an extractor, and let you try it while defining the pattern (with the "Try" button next to the pattern input field). I didn't put enough emphasis on this feature in my post, though.
So it still fails silently when the log format changes slightly, e.g. upstream fixes spelling or grammar in one of the log messages produced.