# Checking Field Length

**URL:** <https://discuss.elastic.co/t/checking-field-length/51335>\
**Category:** Logstash\
**Created:** [May 30, 2016, 3:22pm UTC](https://discuss.elastic.co/t/checking-field-length/51335 "2016-05-30T15:22:52Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![wmikew5672](https://avatars.discourse-cdn.com/v4/letter/w/58956e/32.png) [@wmikew5672](https://discuss.elastic.co/u/wmikew5672)\
**Post date:** [May 30, 2016, 3:22pm UTC](https://discuss.elastic.co/t/checking-field-length/51335/1 "2016-05-30T15:22:52Z")

</div>

I'm still relatively new to Logstash, and I'm looking to find a way to check the length of an error message within a filter. If the message exceeds a defined number of characters, I want to output to an alternate ES index, and if it's within the defined parameters, simply send it to our normal index. Is this possible, and if so, what is the best approach?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 31, 2016, 7:50am UTC](https://discuss.elastic.co/t/checking-field-length/51335/2 "2016-05-31T07:50:06Z")

</div>

This is possible but you need to use a ruby filter. This untested snippet stores the desired index name in a new field:

```nohighlight
filter {
  ruby {
    code => "
      event['indexname'] = event['somefield'].length > 10 ? 'long-fields' : 'short-fields'
    "
  }
}

```

---

<div class="post-metadata">

**Author:** ![wmikew5672](https://avatars.discourse-cdn.com/v4/letter/w/58956e/32.png) [@wmikew5672](https://discuss.elastic.co/u/wmikew5672)\
**Post date:** [May 31, 2016, 11:09am UTC](https://discuss.elastic.co/t/checking-field-length/51335/3 "2016-05-31T11:09:31Z")

</div>

Thanks for the assistance Magnus!

---

<div class="post-metadata">

**Author:** ![wmikew5672](https://avatars.discourse-cdn.com/v4/letter/w/58956e/32.png) [@wmikew5672](https://discuss.elastic.co/u/wmikew5672)\
**Post date:** [May 31, 2016, 12:00pm UTC](https://discuss.elastic.co/t/checking-field-length/51335/4 "2016-05-31T12:00:28Z")

</div>

Sorry Magnus, but I'm just a little confused still as to how I define the index it will revert to. I assume  
'long-fields' : 'short-fields' will accomplish this, with one of them defining the index  
depending on how the condition resolves, but in my output to elasticsearch,  
how is this accomplished?

output {  
elasticsearch {  
hosts =\> ["my-hosts"]  
index =\> " **What goes here** -%{+YYYY-MM}" # Should I put "[event['indexname']]-%{+YYYY-MM}" here?  
user =\> "user"  
password =\> "pwd"  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 31, 2016, 1:43pm UTC](https://discuss.elastic.co/t/checking-field-length/51335/5 "2016-05-31T13:43:10Z")

</div>

This is what you're looking for:

```
index => "%{indexname}-%{+YYYY-MM}"

```

You might want to store the index name in a `@metadata` field instead so it doesn't end up in the event sent to Elasticsearch.

See [https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#logstash-config-field-references](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#logstash-config-field-references).

---

<div class="post-metadata">

**Author:** ![wmikew5672](https://avatars.discourse-cdn.com/v4/letter/w/58956e/32.png) [@wmikew5672](https://discuss.elastic.co/u/wmikew5672)\
**Post date:** [May 31, 2016, 2:42pm UTC](https://discuss.elastic.co/t/checking-field-length/51335/6 "2016-05-31T14:42:04Z")

</div>

Thanks again!

---

<div class="post-metadata">

**Author:** ![rakesh](https://avatars.discourse-cdn.com/v4/letter/r/258eb7/32.png) [@rakesh](https://discuss.elastic.co/u/rakesh)\
**Post date:** [June 23, 2017, 4:07am UTC](https://discuss.elastic.co/t/checking-field-length/51335/7 "2017-06-23T04:07:48Z")

</div>

How can I trim all the fields in message based on a particular length? Lets say I have a very huge stack trace.  
So if I have a stack trace like aabcd..... , I want to take the first 30k characters of a field and truncate the remaining characters,  
If I want to index that in ES it has a limit of 32766 for storing it as a string.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 26, 2017, 9:15pm UTC](https://discuss.elastic.co/t/checking-field-length/51335/8 "2017-06-26T21:15:34Z")

</div>

@rakesh, please start a new thread instead of resurrecting this very old one.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 4:21am UTC](https://discuss.elastic.co/t/checking-field-length/51335/9 "2022-11-04T04:21:36Z")

</div>


