# Get 10 characters before substring in logstash?

**URL:** <https://discuss.elastic.co/t/get-10-characters-before-substring-in-logstash/94439>\
**Category:** Logstash\
**Created:** [July 25, 2017, 7:58am UTC](https://discuss.elastic.co/t/get-10-characters-before-substring-in-logstash/94439 "2017-07-25T07:58:45Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yaswanth](https://avatars.discourse-cdn.com/v4/letter/y/94ad74/32.png) [@Yaswanth](https://discuss.elastic.co/u/Yaswanth)\
**Post date:** [July 25, 2017, 7:58am UTC](https://discuss.elastic.co/t/get-10-characters-before-substring-in-logstash/94439/1 "2017-07-25T07:58:45Z")

</div>

Hi,

I want to get the first 10 characters from a string that ends with Exception.  
Example: I have field like this:

```
 "ERRORMESSAGE" => "local exporter [default_local] - failed to delete indice
s\r\nRemoteTransportException[[data-2][10.0.x.x:x300][indices:admin/delete]];
 nested: IndexNotFoundException[no such index];\r\nCaused by: [.marvel-es-1-2017
.06.07] IndexNotFoundException[no such index]\r\n at org.elasticsearch.cl
uster.metadata.MetaDataDeleteIndexService$1.execute(MetaDataDeleteIndexService.j
ava:91)\r\n at org.elasticsearch.cluster.ClusterStateUpdateTask.execute(C
lusterStateUpdateTask.java:45)\r\n at org.elasticsearch.cluster.service.I
nternalClusterService.runTasksForExecutor(InternalClusterService.java:468)\r\n
  at org.elasticsearch.cluster.service.InternalClusterService$UpdateTask.run
(InternalClusterService.java:772)\r\n at org.elasticsearch.common.util.co
ncurrent.PrioritizedEsThreadPoolExecutor$TieBreakingPrioritizedRunnable.runAndCl
ean(PrioritizedEsThreadPoolExecutor.java:231)\r\n at org.elasticsearch.co
mmon.util.concurrent.PrioritizedEsThreadPoolExecutor$TieBreakingPrioritizedRunna
ble.run(PrioritizedEsThreadPoolExecutor.java:194)\r\n at java.util.concur
rent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1142)\r\n at ja
va.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:617)\r\
n at java.lang.Thread.run(Thread.java:745)\r",

```

Where i need to catch the string that ends with Exception. For that i had used this

```
grok {
  match => ["ERRORMESSAGE", "(?<ExceptionType>{10}.Exception)"]
}

```

Where i am finding the first 10 characters of a string that ends with Exception but i am getting this error `{:exception=>"RegexpError"` . And also other problem is if there are more strings that ends with Exception in `ERRORTYPE` field then whether above grok produces two or more `ExceptionType` fields ?

Thanks

---

<div class="post-metadata">

**Author:** ![R-Ali](https://avatars.discourse-cdn.com/v4/letter/r/8e8cbc/32.png) [@R-Ali](https://discuss.elastic.co/u/R-Ali)\
**Post date:** [July 25, 2017, 8:08am UTC](https://discuss.elastic.co/t/get-10-characters-before-substring-in-logstash/94439/2 "2017-07-25T08:08:33Z")

</div>

Hello,

You can use ruby filter.  
Example:  
ruby {   
code =\> "  
new\_value = event.get('ERRORMESSAGE')[0..10]  
event.set('ERRORMESSAGE',new\_value)  
"  
}

Ali

---

<div class="post-metadata">

**Author:** ![Yaswanth](https://avatars.discourse-cdn.com/v4/letter/y/94ad74/32.png) [@Yaswanth](https://discuss.elastic.co/u/Yaswanth)\
**Post date:** [July 25, 2017, 8:11am UTC](https://discuss.elastic.co/t/get-10-characters-before-substring-in-logstash/94439/3 "2017-07-25T08:11:02Z")

</div>

Thanks @R-Ali

But what i want is different i want first 10 characters from a substring in `ERRORTYPE` field where the substring ends with Exception .

EX: "ERRORTYPE" : "The exception name is INDEXNOTFOUNDException"

Then i need to get "ErrorType" : INDEXNOTFOUNDException

Ref: [How do perform string manipulations](https://discuss.elastic.co/t/how-do-perform-string-manipulations/32706/2)

Thanks

---

<div class="post-metadata">

**Author:** ![R-Ali](https://avatars.discourse-cdn.com/v4/letter/r/8e8cbc/32.png) [@R-Ali](https://discuss.elastic.co/u/R-Ali)\
**Post date:** [July 25, 2017, 8:34am UTC](https://discuss.elastic.co/t/get-10-characters-before-substring-in-logstash/94439/4 "2017-07-25T08:34:17Z")

</div>

Ah ok.  
You can something like this

> ruby {   
> code =\> "  
> ERRORTYPE = event.get('ERRORMESSAGE').match('/Exception/')[0]  
> ERRORTYPE = ERRORTYPE [0..10]  
> event.set('ERRORTYPE ',ERRORTYPE )  
> "  
> }

I'm not sure for the match function (you need to see ruby documentation) But the idea is good 🙂

---

<div class="post-metadata">

**Author:** ![Yaswanth](https://avatars.discourse-cdn.com/v4/letter/y/94ad74/32.png) [@Yaswanth](https://discuss.elastic.co/u/Yaswanth)\
**Post date:** [July 25, 2017, 8:45am UTC](https://discuss.elastic.co/t/get-10-characters-before-substring-in-logstash/94439/5 "2017-07-25T08:45:47Z")

</div>

Thanks @R-Ali

It is not showing any error but it is not giving `ERRORTYPE` field in the output.

Thanks

---

<div class="post-metadata">

**Author:** ![R-Ali](https://avatars.discourse-cdn.com/v4/letter/r/8e8cbc/32.png) [@R-Ali](https://discuss.elastic.co/u/R-Ali)\
**Post date:** [July 25, 2017, 10:33am UTC](https://discuss.elastic.co/t/get-10-characters-before-substring-in-logstash/94439/6 "2017-07-25T10:33:16Z")

</div>

You need to put this code after grok filter  
I do some correction :

> ruby {  
> code =\> "  
> error\_type = event.get('ERRORMESSAGE').match(/Exception/)[0]  
> error\_type = ERRORTYPE [0..10]  
> event.set('ERRORTYPE ',error\_type )  
> "  
> }

---

<div class="post-metadata">

**Author:** ![Yaswanth](https://avatars.discourse-cdn.com/v4/letter/y/94ad74/32.png) [@Yaswanth](https://discuss.elastic.co/u/Yaswanth)\
**Post date:** [July 25, 2017, 10:35am UTC](https://discuss.elastic.co/t/get-10-characters-before-substring-in-logstash/94439/7 "2017-07-25T10:35:42Z")

</div>

Thanks @R-Ali

I changed my grok like this

```
 grok {
  match => ["ERRORMESSAGE", "(?<ExceptionType>.{13}Exception)"]
}

```

And it worked fine. Thanks for helping me.  
Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 22, 2017, 10:35am UTC](https://discuss.elastic.co/t/get-10-characters-before-substring-in-logstash/94439/8 "2017-08-22T10:35:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
