# Field list

**URL:** <https://discuss.elastic.co/t/field-list/214863>\
**Category:** Logstash\
**Created:** [January 13, 2020, 3:48pm UTC](https://discuss.elastic.co/t/field-list/214863 "2020-01-13T15:48:48Z")\
**Posts on this page:** 1\
**Showing post:** 10

<div class="post-metadata">

**Author:** ![andres-perez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andres-perez/32/136461_2.png) [@andres-perez](https://discuss.elastic.co/u/andres-perez)\
**Post date:** [January 14, 2020, 5:13pm UTC](https://discuss.elastic.co/t/field-list/214863/10 "2020-01-14T17:13:09Z")

</div>

> [@volcano](#):
>
> Is this syntactically okay now ?

You can just [run logstash from command line](https://www.elastic.co/guide/en/logstash/current/running-logstash-command-line.html) with **`--config.test_and_exit`** to check syntax.

If you are comfortable using docker containers on your own you can use this tool [Web-UI for Logstash filter development](https://discuss.elastic.co/t/web-ui-for-logstash-filter-development/209748)

Either way you can test it and if it throws an error, **paste here all the details** :

- log contents used as input
- logstash configuration
- errors, desired or unexpected output

In fact, if you paste here a sample log line it would be really useful. I presume that, instead of splitting a message in two by a word separator, splitting the result in two again by another word, splitting again by other separators... is a contrieved way to extract the desired information. Maybe grok or kv filters are a simpler solution for your use case.

---

_[View the full topic](https://discuss.elastic.co/t/field-list/214863)._
