# Formatting strings using scripted fields - inserting line breaks

**URL:** <https://discuss.elastic.co/t/formatting-strings-using-scripted-fields-inserting-line-breaks/138242>\
**Category:** Kibana\
**Created:** [July 2, 2018, 4:44pm UTC](https://discuss.elastic.co/t/formatting-strings-using-scripted-fields-inserting-line-breaks/138242 "2018-07-02T16:44:54Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Warren](https://avatars.discourse-cdn.com/v4/letter/w/97f17d/32.png) [@Warren](https://discuss.elastic.co/u/Warren)\
**Post date:** [July 2, 2018, 4:44pm UTC](https://discuss.elastic.co/t/formatting-strings-using-scripted-fields-inserting-line-breaks/138242/1 "2018-07-02T16:44:55Z")

</div>

My 'message' contains a stacktrace / exception error like below.  
But the string is not easy to read in Kibana. I need to insert new lines on each trace line.. so it's neat and tidy etc..  
I've read that I can use scripted fields to achieve this, and the painless would look like this?

doc['message'].value = "\n" + "  
"

But the script does not work. How can I replace \n in the strack trace so my messages are on new lines in Kibana?

[2018-06-07 11:02:33] testing.ERROR: Class 'App\Http\Controllers\Deal' not found {"exception":"[object] (Symfony\Component\Debug\Exception\FatalThrowableError(code: 0): Class 'App\Http\Controllers\Deal' not found at /app/Http/Controllers/TestingSyslogController.php:13)\n[stacktrace]\n#0 [internal function]: App\Http\Controllers\TestingSyslogController-\>index()\n#1 /vendor/laravel/framework/src/Illuminate/Routing/Controller.php(54): call\_user\_func\_array(Array, Array)\n#2 /vendor/laravel/framework/src/Illuminate/Routing/ControllerDispatcher.php(45): Illuminate\Routing\Controller-\>callAction('index', Array)\n#3 /vendor/laravel/framework/src/Illuminate/Routing/Route.php(212): Illuminate\Routing\ControllerDispatcher-\>dispatch(Object(Illuminate\Routing\Route), Object(App\Http\Controllers\TestingSyslogController), 'index')\n#4 /vendor/laravel/framework/src/Illuminate/Routing/Route.php(169): Illuminate\Routing\Route-\>runController()\n#5

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [July 2, 2018, 5:13pm UTC](https://discuss.elastic.co/t/formatting-strings-using-scripted-fields-inserting-line-breaks/138242/2 "2018-07-02T17:13:21Z")

</div>

You can write a formatter function that truncated the line or splits it with a line-break (using HTML   
 tag).([https://www.elastic.co/guide/en/kibana/current/scripted-fields.html](https://www.elastic.co/guide/en/kibana/current/scripted-fields.html) )( available 5.0 and above)

CHeers  
Rashmi

---

<div class="post-metadata">

**Author:** ![Warren](https://avatars.discourse-cdn.com/v4/letter/w/97f17d/32.png) [@Warren](https://discuss.elastic.co/u/Warren)\
**Post date:** [July 2, 2018, 6:02pm UTC](https://discuss.elastic.co/t/formatting-strings-using-scripted-fields-inserting-line-breaks/138242/3 "2018-07-02T18:02:31Z")

</div>

I'll convert this inline script to scripted fields I guess

[https://www.elastic.co/guide/en/x-pack/5.5/ml-configuring-transform.html#ml-configuring-transform6](https://www.elastic.co/guide/en/x-pack/5.5/ml-configuring-transform.html#ml-configuring-transform6)

Amazed there are no working examples of stack trace handling in kibana. I tried logstash & grok filtering already.... was hoping this scripted fields might offer a good alternative.

I might just write a custom log in json format and send it directly to logstash.

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [July 2, 2018, 7:57pm UTC](https://discuss.elastic.co/t/formatting-strings-using-scripted-fields-inserting-line-breaks/138242/4 "2018-07-02T19:57:50Z")

</div>

> [@Warren](#):
>
> of stack trace handling in kibana. I tried logstash & grok filtering already.... was hoping this scripted fields might offer a good alternative.
> 
> I might just write a custom log in json format and send it directly to logstash.

You need to parse that at index time itself. Scripted field will get you there, and is the only option if it's already indexed, but not a prob for Kibana to solve, the workflow for that is done pre-kibana.

Cheers  
Rashmi

---

<div class="post-metadata">

**Author:** ![Warren](https://avatars.discourse-cdn.com/v4/letter/w/97f17d/32.png) [@Warren](https://discuss.elastic.co/u/Warren)\
**Post date:** [July 3, 2018, 12:56am UTC](https://discuss.elastic.co/t/formatting-strings-using-scripted-fields-inserting-line-breaks/138242/5 "2018-07-03T00:56:27Z")

</div>

I've tried scripted fields, I've used lang=painless, type=string, format=string,  
script=/\n/.matcher(doc['message'].value).replaceAll('  
')

but then I receive this error  
"Courier Fetch: 10 of 715 shards failed.

The script might be written wrong...

I've tried

1. doc['message'].value = "\n" + "  

2. /\n/.matcher(doc['message'].value).replaceAll('  
')

Wondering how I can debug or test a scripted field......

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 31, 2018, 12:56am UTC](https://discuss.elastic.co/t/formatting-strings-using-scripted-fields-inserting-line-breaks/138242/6 "2018-07-31T00:56:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
