# Filter Logstash syslog

**URL:** <https://discuss.elastic.co/t/filter-logstash-syslog/110429>\
**Category:** Logstash\
**Created:** [December 5, 2017, 10:08pm UTC](https://discuss.elastic.co/t/filter-logstash-syslog/110429 "2017-12-05T22:08:13Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![yayitaing](https://avatars.discourse-cdn.com/v4/letter/y/df705f/32.png) [@yayitaing](https://discuss.elastic.co/u/yayitaing)\
**Post date:** [December 5, 2017, 10:08pm UTC](https://discuss.elastic.co/t/filter-logstash-syslog/110429/1 "2017-12-05T22:08:13Z")

</div>

I have the following message that is displayed in the kibana brought by filebeat from a linux syslog:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/e/7e6d0feab42e221fcf7c86da91f8499e7b7eb01f.png)

However, I need each field of the message to be shown in the kibana as an independent field to be able to perform metrics, for example the user field:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/5/d557ea909676cb962e878a2e7a6e41dc04604552.png)

The configuration of my filter in logstash is the following:

![image](https://us1.discourse-cdn.com/elastic/original/3X/a/9/a912ec6834f14171058f85d0215ccc4cd6795662.png)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 5, 2017, 11:44pm UTC](https://discuss.elastic.co/t/filter-logstash-syslog/110429/2 "2017-12-05T23:44:46Z")

</div>

SYSLOGLINE names the parsed message field "message". That field name is the source message, so you end up with an array. This should get you started:

```
filter {
  grok {
    match => { "message" => "%{SYSLOGLINE}" }
  }
  if [message][1] { kv { source => "[message][1]" } }
}
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 6, 2017, 6:30am UTC](https://discuss.elastic.co/t/filter-logstash-syslog/110429/3 "2017-12-06T06:30:08Z")

</div>

With `overwrite => ["message"]` in the grok filter the `message` field won't become an array.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 3, 2018, 6:30am UTC](https://discuss.elastic.co/t/filter-logstash-syslog/110429/4 "2018-01-03T06:30:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
