# Concatenate message header and content, parse message content

**URL:** <https://discuss.elastic.co/t/concatenate-message-header-and-content-parse-message-content/360077>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 23, 2024, 1:01pm UTC](https://discuss.elastic.co/t/concatenate-message-header-and-content-parse-message-content/360077 "2024-05-23T13:01:03Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![tohkoecalo](https://avatars.discourse-cdn.com/v4/letter/t/bbe5ce/32.png) [@tohkoecalo](https://discuss.elastic.co/u/tohkoecalo)\
**Post date:** [May 23, 2024, 1:01pm UTC](https://discuss.elastic.co/t/concatenate-message-header-and-content-parse-message-content/360077/1 "2024-05-23T13:01:03Z")

</div>

I setup filebeat to send logs to elasticsearch but for now I have two problems.  
First, I receive my message header and content in two separate records. In Kibana interface they are shown like this:

 ![Screenshot 2024-05-23 at 17.50.26](https://us1.discourse-cdn.com/elastic/original/3X/2/0/2003aecc6fe0874ef86ba1ea0806c997d454fa0f.png)  
But in source file this is one record:  
 ![Screenshot 2024-05-23 at 17.54.59](https://us1.discourse-cdn.com/elastic/original/3X/2/b/2be42c067256f183a1210efea6e9e5369917a3c1.png)  
The second problem is, that I want to parse message content and get its separate parts in different columns in Kibana. I tried to do it with dissect processor, but no fields are present in message details. My filebeat config yml file:

```auto
filebeat.config:
  modules:
    path: ${path.config}/modules.d/*.yml
    reload.enabled: false

filebeat.inputs:
- type: log
  paths:
    - /usr/share/filebeat/logs/app.log
  pattern: '^[[:space:]]'
  negate: false
  match: after

processors:
  - add_host_metadata: ~
  - dissect:
      tokenizer: '%{@timestamp} [%{service.pid}] %{log.logger} [%{service.thread_id}] [%{log.level}] %{message}'
      field: "message"
      target_prefix: ""
  - timestamp:
      field: "@timestamp"
      layouts:
        - '2006-01-02T15:04:05,999'
      test:
        - '2024-05-23T14:57:14,818'

output.elasticsearch:
  hosts: '${ELASTICSEARCH_HOSTS:127.0.0.1:9200}'
  username: '${ELASTICSEARCH_USERNAME:elastic}'
  password: '${ELASTICSEARCH_PASSWORD:elastic}'

```

And the message details are:

 ![Screenshot 2024-05-23 at 17.59.47](https://us1.discourse-cdn.com/elastic/original/3X/4/6/467c18ee8bc612eb81c9888b6c44a01e3b4486a1.png)  
Can I parse my message with filebeat itself or I need to use Grok? Can I also show my message header and content as a single record?
