# Create new field from existing message match grok filter

**URL:** <https://discuss.elastic.co/t/create-new-field-from-existing-message-match-grok-filter/216387>\
**Category:** Logstash\
**Created:** [January 24, 2020, 8:09am UTC](https://discuss.elastic.co/t/create-new-field-from-existing-message-match-grok-filter/216387 "2020-01-24T08:09:52Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![dhody\_rhmd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dhody_rhmd/32/58823_2.png) [@dhody\_rhmd](https://discuss.elastic.co/u/dhody_rhmd)\
**Post date:** [January 24, 2020, 8:09am UTC](https://discuss.elastic.co/t/create-new-field-from-existing-message-match-grok-filter/216387/1 "2020-01-24T08:09:52Z")

</div>

I have a log looks like this

> 2020-01-24 06:49:05] local.ERROR: syntax error, unexpected ''/home);' (T\_ENCAPSED\_AND\_WHITESPACE) {"exception":"[object] (Symfony\Component\Debug\Exception\FatalThrowableError(code: 0): syntax error, unexpected ''/home);' (T\_ENCAPSED\_AND\_WHITESPACE) at /var/www/html/test.com/app/Http/Controllers/HomeController.php:10)

and i have filter conf looks like this

```
        filter
    {
        grok {
            match => { "message" => "\[%{TIMESTAMP_ISO8601:timestamp}\] %{DATA:env}\.%{DATA:severity}\: %{GREEDYDATA:issue}" }
        }
        mutate {
            add_field => {
                "opsgenieAction" => "create"
                "description" => "EMERGENCY"
                "actions" => ["Restart", "Fixing Bug"]
                "tags" => ["Error"]
                "[details][prop1]" => "val1"
                "[details][prop2]" => "val2"
                "entity" => "Laravel Application"
                "priority" => "P1"
                "source" => "ce006"
                "user" => "custom user"
                "note" => "alert is created"
            }
        }
    }

```

the grok match filter give back the result

> "message" =\> "{"@timestamp":"2020-01-24T07:46:58.365088+00:00","@source":"ce006","@fields":{"channel":"local","level":400,"ctxt\_exception":{"class":"Symfony\\Component\\Debug\\Exception\\FatalThrowableError","message":"syntax error, unexpected ''/home);' (T\_ENCAPSED\_AND\_WHITESPACE)","code":0,"file":"/var/www/html/test.com/app/Http/Controllers/HomeController.php:10","trace":.....  
> "@issue":"syntax error, unexpected ''/home);' (T\_ENCAPSED\_AND\_WHITESPACE)","@tags":["local"]}\n",

I want to extract the issue element and overwrite the message match filter so i just got the issue about whats happening on my application. any suggestion how to do this?

---

<div class="post-metadata">

**Author:** ![dhody\_rhmd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dhody_rhmd/32/58823_2.png) [@dhody\_rhmd](https://discuss.elastic.co/u/dhody_rhmd)\
**Post date:** [January 24, 2020, 8:13am UTC](https://discuss.elastic.co/t/create-new-field-from-existing-message-match-grok-filter/216387/2 "2020-01-24T08:13:28Z")

</div>

I want the message to be just

> syntax error, unexpected ''/home);' (T\_ENCAPSED\_AND\_WHITESPACE)","@tags":["local"]}\n

instead of

> {"@timestamp":"2020-01-24T07:46:58.365088+00:00","@source":"ce006","@fields":{"channel":"local","level":400,"ctxt\_exception":{"class":"Symfony\Component\Debug\Exception\FatalThrowableError","message":"syntax error, unexpected ''/home);' (T\_ENCAPSED\_AND\_WHITESPACE)","code":0,"file":"/var/www/html/test.com/app/Http/Controllers/HomeController.php:10","trace":.....  
> "@issue":"syntax error, unexpected ''/home);' (T\_ENCAPSED\_AND\_WHITESPACE)","@tags":["local"]}\n",

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 21, 2020, 8:13am UTC](https://discuss.elastic.co/t/create-new-field-from-existing-message-match-grok-filter/216387/3 "2020-02-21T08:13:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
