# Help for space separate message

**URL:** <https://discuss.elastic.co/t/help-for-space-separate-message/211672>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 12, 2019, 2:53pm UTC](https://discuss.elastic.co/t/help-for-space-separate-message/211672 "2019-12-12T14:53:11Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Patricio\_Campos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patricio_campos/32/46188_2.png) [@Patricio\_Campos](https://discuss.elastic.co/u/Patricio_Campos)\
**Post date:** [December 12, 2019, 2:53pm UTC](https://discuss.elastic.co/t/help-for-space-separate-message/211672/1 "2019-12-12T14:53:11Z")

</div>

Hello,  
am new in Elastic, am working with SIEM module. I receive a log from Fortinet Firewall through a Rsyslog Linux and filebeat receive and send to Elasticsearcg, all importants field come in one large field named Message. I would like separate this information for example src\_ip, src\_port, etc etc

**date=2019-12-12 time=11:31:33 devname="Fwr1-Kaufmann" devid="FGT6HD3916801908" logid="0000000013" type="traffic" subtype="forward" level="notice" vd="root" eventtime=1576161093 srcip=10.1.1.9 srcport=54091 srcintf="LACP\_Interna" srcintfrole="undefined" dstip=208.67.222.222 dstport=53 dstintf="port10" dstintfrole="undefined" poluuid="0f497e7c-5f9a-51e8-2401-1473957296a8" sessionid=796002608 proto=17 action="accept" policyid=402 policytype="policy" service="DNS" dstcountry="United States" srccountry="Reserved" trandisp="snat" transip=190.216.145.133 transport=54091 duration=60 sentbyte=72 rcvdbyte=88 sentpkt=1 rcvdpkt=1 appcat="unscanned"**

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [December 13, 2019, 10:01am UTC](https://discuss.elastic.co/t/help-for-space-separate-message/211672/2 "2019-12-13T10:01:40Z")

</div>

Hi!

For this you will need to add a Logstash pipeline to further analyse the messages, by defining your own [grok patterns.](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html)

Filebeat can analyse messages from services that are supported by Filebeat's [modules](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-modules-overview.html), but when you need something so custom the best way to go is to add a Logstash node and do the parsing there.

Regards.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 10, 2020, 10:01am UTC](https://discuss.elastic.co/t/help-for-space-separate-message/211672/3 "2020-01-10T10:01:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
