# Field overwrite is not working

**URL:** <https://discuss.elastic.co/t/field-overwrite-is-not-working/107158>\
**Category:** Logstash\
**Created:** [November 10, 2017, 9:00am UTC](https://discuss.elastic.co/t/field-overwrite-is-not-working/107158 "2017-11-10T09:00:45Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ou\_snaaksie](https://avatars.discourse-cdn.com/v4/letter/o/b487fb/32.png) [@ou\_snaaksie](https://discuss.elastic.co/u/ou_snaaksie)\
**Post date:** [November 10, 2017, 9:00am UTC](https://discuss.elastic.co/t/field-overwrite-is-not-working/107158/1 "2017-11-10T09:00:45Z")

</div>

I want to only keep a certain part of a syslog message as the `message`.

```auto
input {
    udp {
        port => "514"
        type => "syslog-cisco"
    }

    tcp {
        port => "514"
        type => "syslog-cisco"
    }
}

filter {
    grok {
        patterns_dir => ["../patterns"]
        match => [
            "message", "%{SYSLOG5424PRI}(%{NUMBER:log_sequence#})?:( %{NUMBER}:)? %{CISCOTIMESTAMPTZ:log_date}: %%{SYSLOGPROG:facility}-%{INT:severity_level}-%{SYSLOGPROG:facility_mnemonic}: %{GREEDYDATA:message}",
            "message", "%{SYSLOG5424PRI}(%{NUMBER:log_sequence#})?:( %{NUMBER}:)? %{CISCOTIMESTAMPTZ:log_date}: %%{SYSLOGPROG:facility}-%{SYSLOGPROG:facility_sub}-%{INT:severity_level}-%{SYSLOGPROG:facility_mnemonic}: %{GREEDYDATA:message}"
        ]

        overwrite => ["message"]
        add_tag => ["cisco-ios"]
        add_tag => ["cisco"]
        remove_field => ["syslog5424_pri", "@version"]
    } # grok

    if "cisco-ios" not in [tags] {
        mutate {
            remove_tag => ["_grokparsefailure"]
        }

        grok {
            patterns_dir => ["../patterns"]
            match => [
                "message", "%{SYSLOG5424PRI}(%{HOSTNAME:hostname})?:( \*%{SYSLOGPROG:facility}:) (%{CISCOTIMESTAMP:log_date}:) (%%{SYSLOGPROG:facility_sub}:) %{GREEDYDATA: message}"
            ]

            overwrite => ["message"]
            add_tag => ["cisco-wlc"]
            add_tag => ["cisco"]
            remove_field => ["@version", "program"]
        } # grok
    } # if
} # filter

output {
    elasticsearch {
        hosts => ["localhost:9200"]
        index => "network-%{+YYYY.MM.dd}"
    }
}

```

In the firstt `grok{}` it works, and only `%{GREEDYDATA:message}` gets assigned to `message` in the overwrite, but for some reason, it is not happening with the second one.  
Why?

EDIT:  
This is what the syslog message for the second `grok{}` looks like:  
`<182>HOST001: *radiusTransportThread: Nov 10 10:02:22.149: %AAA-6-RADIUS_IN_GLOBAL_LIST: [PA]radius_db.c:426 RADIUS server 172.20.1.84:1813 activated in global list`

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 10, 2017, 9:13am UTC](https://discuss.elastic.co/t/field-overwrite-is-not-working/107158/2 "2017-11-10T09:13:32Z")

</div>

> [@ou\_snaaksie](#):
>
> %{GREEDYDATA: message}"

You seem to have a space in there just before `message`. Is that causing this?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 8, 2017, 9:13am UTC](https://discuss.elastic.co/t/field-overwrite-is-not-working/107158/3 "2017-12-08T09:13:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
