# Filebeat: Split message field in kibana into several fields

**URL:** <https://discuss.elastic.co/t/filebeat-split-message-field-in-kibana-into-several-fields/196676>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 25, 2019, 7:36pm UTC](https://discuss.elastic.co/t/filebeat-split-message-field-in-kibana-into-several-fields/196676 "2019-08-25T19:36:31Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![O\_K](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/o_k/32/52424_2.png) [@O\_K](https://discuss.elastic.co/u/O_K)\
**Post date:** [August 25, 2019, 7:36pm UTC](https://discuss.elastic.co/t/filebeat-split-message-field-in-kibana-into-several-fields/196676/1 "2019-08-25T19:36:31Z")

</div>

Do I need logstash to transform below log message received in Kibana from filebeat

> [2019-08-25T19:23:07.489Z] "GET /health HTTP/1.1" 200 - "-" "-" 0 15 22 22 "-" "kube-probe/1.13" "68e1cfbd-345f-45cd-9b86-2b4b17ab3ade" "172.30.35.252:8080" "127.0.0.1:8061" inbound|8080|http-management|kube-appname-app-service.default.svc.cluster.local - 172.30.35.252:8080 10.135.231.188:22451 -

TO several columns

> HTTP METHOD|DIRECTION|PORT|OPERATION|SERVICE\_NAME  
> 200|inbound|8080|http-management|kube-appname-app-service.default.svc.cluster.local

I know this is possible to do with logstash grok+filter, but I'm not sure whether this could be done only with filebeat:

Much appreciate!!!

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [August 27, 2019, 5:47pm UTC](https://discuss.elastic.co/t/filebeat-split-message-field-in-kibana-into-several-fields/196676/2 "2019-08-27T17:47:02Z")

</div>

Hi @O_K,

You could probably do it using Filebeat processors, there is for example one to [decode CSV fields](https://www.elastic.co/guide/en/beats/filebeat/7.3/decode-csv-fields.html), that was introduced in filebeat 7.2 and is able to split a string using a custom separator. The [dissect processor](https://www.elastic.co/guide/en/beats/filebeat/7.3/dissect.html) can also be helpful to separate the rest of elements.

If you want to use grok, you can also [use Elasticsearch ingest nodes](https://www.elastic.co/guide/en/beats/filebeat/7.3/configuring-ingest-node.html) instead of Logstash. They allow to define [pipelines](https://www.elastic.co/guide/en/elasticsearch/reference/7.3/pipeline.html) similar to the ones you could define with Logstash.

---

<div class="post-metadata">

**Author:** ![O\_K](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/o_k/32/52424_2.png) [@O\_K](https://discuss.elastic.co/u/O_K)\
**Post date:** [August 27, 2019, 6:02pm UTC](https://discuss.elastic.co/t/filebeat-split-message-field-in-kibana-into-several-fields/196676/3 "2019-08-27T18:02:17Z")

</div>

Thank you @jsoriano,

Does it mean filebeat could be enough for some aggregation? Or we still have to use logstash/fluentd?

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [August 27, 2019, 6:03pm UTC](https://discuss.elastic.co/t/filebeat-split-message-field-in-kibana-into-several-fields/196676/4 "2019-08-27T18:03:54Z")

</div>

What kind of aggregations?

---

<div class="post-metadata">

**Author:** ![O\_K](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/o_k/32/52424_2.png) [@O\_K](https://discuss.elastic.co/u/O_K)\
**Post date:** [August 27, 2019, 6:17pm UTC](https://discuss.elastic.co/t/filebeat-split-message-field-in-kibana-into-several-fields/196676/5 "2019-08-27T18:17:52Z")

</div>

Let's say for below I'd like to get sum of 200 http methods for particular SERVICE\_NAME

```
HTTP METHOD|DIRECTION|PORT|OPERATION|SERVICE_NAME
200|inbound|8080|http-management|kube-appname-app-service.default.svc.cluster.local
```

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [August 28, 2019, 9:19am UTC](https://discuss.elastic.co/t/filebeat-split-message-field-in-kibana-into-several-fields/196676/6 "2019-08-28T09:19:36Z")

</div>

Oh, you could use Kibana to explore the data collected by filebeat, what includes aggregations. Aggregations would be done at query time.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 25, 2019, 9:25am UTC](https://discuss.elastic.co/t/filebeat-split-message-field-in-kibana-into-several-fields/196676/7 "2019-09-25T09:25:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
