# Checking length of a message

**URL:** <https://discuss.elastic.co/t/checking-length-of-a-message/154044>\
**Category:** Logstash\
**Created:** [October 25, 2018, 4:50pm UTC](https://discuss.elastic.co/t/checking-length-of-a-message/154044 "2018-10-25T16:50:00Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Parvatayya\_Malimath](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/parvatayya_malimath/32/49330_2.png) [@Parvatayya\_Malimath](https://discuss.elastic.co/u/Parvatayya_Malimath)\
**Post date:** [October 25, 2018, 4:50pm UTC](https://discuss.elastic.co/t/checking-length-of-a-message/154044/1 "2018-10-25T16:50:00Z")

</div>

Hi

I am creating logstash filter, for a message like below  
10.134.246.236 - **username** [24/Oct/2018:15:51:39 +0200] "POST /xyz/xyz/xyz/

i need to create a filter, which will check the length of **username** and create a tag (long or short) or create a field like long-username or short--username

i am kind of new to logstash and need help

My logstash conf looks like this

input {  
stdin { }  
}

filter {  
grok {  
match =\> { "message" =\> "%{IP:client\_ip} - %{USERNAME :user}-" }  
}

date {  
match =\> ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]  
}  
}

output {  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [October 25, 2018, 5:49pm UTC](https://discuss.elastic.co/t/checking-length-of-a-message/154044/2 "2018-10-25T17:49:25Z")

</div>

Seems like the [Range](https://www.elastic.co/guide/en/logstash/current/plugins-filters-range.html) filter should do what you need.

---

<div class="post-metadata">

**Author:** ![Parvatayya\_Malimath](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/parvatayya_malimath/32/49330_2.png) [@Parvatayya\_Malimath](https://discuss.elastic.co/u/Parvatayya_Malimath)\
**Post date:** [October 26, 2018, 7:09am UTC](https://discuss.elastic.co/t/checking-length-of-a-message/154044/3 "2018-10-26T07:09:17Z")

</div>

i dont have the plugin and no internet access from the machine. so is there a work around or something?

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [October 29, 2018, 2:37pm UTC](https://discuss.elastic.co/t/checking-length-of-a-message/154044/4 "2018-10-29T14:37:41Z")

</div>

[https://www.elastic.co/guide/en/logstash/current/offline-plugins.html](https://www.elastic.co/guide/en/logstash/current/offline-plugins.html)

---

<div class="post-metadata">

**Author:** ![Parvatayya\_Malimath](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/parvatayya_malimath/32/49330_2.png) [@Parvatayya\_Malimath](https://discuss.elastic.co/u/Parvatayya_Malimath)\
**Post date:** [October 29, 2018, 2:40pm UTC](https://discuss.elastic.co/t/checking-length-of-a-message/154044/5 "2018-10-29T14:40:23Z")

</div>

I just used this. 'event.set("new\_field", event.get("some\_field").length())' in ruby filter  
Thanks anyway

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 26, 2018, 2:42pm UTC](https://discuss.elastic.co/t/checking-length-of-a-message/154044/6 "2018-11-26T14:42:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
