# FileBeat + Rails Log

**URL:** <https://discuss.elastic.co/t/filebeat-rails-log/236420>\
**Category:** Elastic Stack\
**Created:** [June 9, 2020, 9:47pm UTC](https://discuss.elastic.co/t/filebeat-rails-log/236420 "2020-06-09T21:47:46Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Andres\_Barcenas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andres_barcenas/32/70026_2.png) [@Andres\_Barcenas](https://discuss.elastic.co/u/Andres_Barcenas)\
**Post date:** [June 9, 2020, 9:47pm UTC](https://discuss.elastic.co/t/filebeat-rails-log/236420/1 "2020-06-09T21:47:46Z")

</div>

I have a very custom rails log with contains some text and a JSON string at the end. Can I use filebeat to dissect/process the file so I can send a proper message to elastic cloud? Here is an example of the message and what I've added the filebeat.yml but it does not work:

[2020-06-09T17:44:42-04:00] [f0345957-5fd6-4998-9972-e02c9cc24419] [127.0.0.1] [localhost] {"method":"GET","path":"/wait\_times/FL","format":"xml","controller":"WaitTimesController","action":"show","status":200,"duration":119.22,"view":0.74,"db":83.13,"params":{"state\_abbrev":"FL"},"time":"2020-06-09 17:44:42 -0400","uuid":"f0345957-5fd6-4998-9972-e02c9cc24419","host":"localhost","remote\_ip":"127.0.0.1","user\_id":53}

```auto
processors:
  - dissect:
      tokenizer: '[%{key1}] [%{key2}] [%{key3}] [%{key4}] {%{key5}}'
      field: "message"
      target_prefix: ""

```

Any help would be greatly appreciated.

-AB

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:01am UTC](https://discuss.elastic.co/t/filebeat-rails-log/236420/2 "2022-11-04T08:01:50Z")

</div>


