# Any Help Un-structure log message to map structure message in Logstash

**URL:** https://discuss.elastic.co/t/any-help-un-structure-log-message-to-map-structure-message-in-logstash/36258
**Category:** Logstash
**Created:** [December 3, 2015, 8:38am UTC](https://discuss.elastic.co/t/any-help-un-structure-log-message-to-map-structure-message-in-logstash/36258 "2015-12-03T08:38:38Z")
**Posts on this page:** 1
**Showing post:** 1

<div class="post-metadata">

### Author: ![jayaram](https://avatars.discourse-cdn.com/v4/letter/j/ecccb3/32.png) [@jayaram](https://discuss.elastic.co/u/jayaram)
#### Post date: [December 3, 2015, 8:38am UTC](https://discuss.elastic.co/t/any-help-un-structure-log-message-to-map-structure-message-in-logstash/36258/1 "2015-12-03T08:38:39Z")

</div>

Hello, I have the log message  
2015-11-18 21:11:38,693 [WARN] [xx.web.common.filter.RequestFilter] NDC[UserPrincipal(ABCDF22602)] request (/member/control/loginAction) exceeded threshold; elapsed milliseconds since start: 188814

Can any one help me. How to tag or map the each same stored/moved to elasticsearch or any output resource

dose GROK plugin help for this mapping? any other plugin available to map/associate the each value to some TAG  
I am trying like this in grok plugin but not working

match =\> { "timestamp" =\> "%{TOMCAT\_DATESTAMP:timestamp}"}  
match =\> { "level" =\> "[%{LOGLEVEL:level}]" }  
match =\> { "class" =\> "[%{JAVACLASS:class}]" }  
match =\> { "logmessage" =\> "%{JAVALOGMESSAGE:logmessage}" }

---

_[View the full topic](https://discuss.elastic.co/t/any-help-un-structure-log-message-to-map-structure-message-in-logstash/36258)._
